PT-2020-9057 · Pki-Core+1 · Pki-Core+1

Published

2020-03-31

·

Updated

2023-02-12

·

CVE-2019-10180

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pki-core versions 10.x.x
Description A vulnerability was found in the Token Processing Service (TPS) where it did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
Recommendations For pki-core versions 10.x.x, ensure that the Token Processing Service (TPS) properly sanitizes parameters stored for the tokens to prevent Stored Cross Site Scripting (XSS) attacks. As a temporary workaround, consider restricting access to the TPS until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-10180
RHSA-2021:0947
RHSA-2021:0948

Affected Products

Debian
Pki-Core