PT-2021-9564 · Tufin · Tufin Securechange

Published

2021-01-20

·

Updated

2021-01-23

·

CVE-2020-13134

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tufin SecureChange versions prior to R19.3 HF3 Tufin SecureChange versions prior to R20-1 HF1
Description The issue is related to stored XSS, which requires admin privileges for storing the XSS payload and can be triggered by admin users. All TOS versions with SecureChange deployments prior to the fixed versions are affected.
Recommendations For versions prior to R19.3 HF3, update to R19.3 HF3 or later to resolve the issue. For versions prior to R20-1 HF1, update to R20-1 HF1 or later to resolve the issue. As a temporary workaround, consider restricting access to admin privileges to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13134

Affected Products

Tufin Securechange