PT-2021-9563 · Tufin · Tufin Securechange
Published
2021-01-20
·
Updated
2021-01-23
·
CVE-2020-13133
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tufin SecureChange versions prior to R19.3 HF3
Tufin SecureChange versions prior to R20-1 HF1
Description
The issue is related to stored XSS, which can be exploited by unauthenticated users, but requires admin privileges to store the XSS payload. All TOS versions with SecureChange deployments prior to the fixed versions are affected.
Recommendations
For versions prior to R19.3 HF3, update to R19.3 HF3 or later to resolve the issue.
For versions prior to R20-1 HF1, update to R20-1 HF1 or later to resolve the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tufin Securechange