PT-2021-9605 · Tufin · Tufin Securetrack
Published
2021-02-09
·
Updated
2021-03-08
·
CVE-2020-13409
CVSS v3.1
5.9
Medium
| Vector | AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Tufin SecureTrack versions prior to R20-2 GA
Description
The issue concerns reflected and stored Cross-Site Scripting (XSS) in Tufin SecureTrack. This allows a malicious non-authenticated user to potentially gain admin-level access. Both stored and reflected payloads can be triggered by an admin, and even a low-privileged user can inject XSS, which can be executed by an admin, potentially elevating privileges and obtaining admin access.
Recommendations
For versions prior to R20-2 GA, update to R20-2 GA or later to resolve the issue. As a temporary workaround, consider restricting access to areas where XSS can be injected to minimize the risk of exploitation. Avoid using the application with admin privileges until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tufin Securetrack