pki-core: Reflected XSS in getcookies?url= endpoint in CA
Published Mar 20, 2020
6.1
MEDIUMCVSS 3.1
EPSS 1.32%
Description
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.
Affected products
- Vendor n/a Product Pki-Core Defaultn/a
- Version all pki-core 10.x.x versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Pki-Core | n/a |
|
Configuration 1
- 7.0
- 8.0
No data.
Red Hat Enterprise Linux 7
pki-core-0:10.5.18-12.el7_9
Fixed · RHSA-2021:0851
Red Hat Enterprise Linux 7.6 Extended Update Support
pki-core-0:10.5.9-15.el7_6
Fixed · RHSA-2021:0819
Red Hat Enterprise Linux 7.7 Extended Update Support
pki-core-0:10.5.16-7.el7_7
Fixed · RHSA-2021:0975
Red Hat Enterprise Linux 8
pki-core:10.6-8030020200911215836.5ff1562f
Fixed · RHSA-2020:4847
Red Hat Enterprise Linux 8
pki-deps:10.6-8030020200527165326.30b713e6
Fixed · RHSA-2020:4847
Red Hat Enterprise Linux 6
pki-core
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | pki-core-0:10.5.18-12.el7_9 | Fixed | RHSA-2021:0851 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | pki-core-0:10.5.9-15.el7_6 | Fixed | RHSA-2021:0819 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | pki-core-0:10.5.16-7.el7_7 | Fixed | RHSA-2021:0975 |
| Red Hat Enterprise Linux 8 | pki-core:10.6-8030020200911215836.5ff1562f | Fixed | RHSA-2020:4847 |
| Red Hat Enterprise Linux 8 | pki-deps:10.6-8030020200527165326.30b713e6 | Fixed | RHSA-2020:4847 |
| Red Hat Enterprise Linux 6 | pki-core | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated Low : the web UI uses client TLS authentication, therefore stealing session cookies will not be sufficient for unauthorized access. The vulnerable page itself does not contain secrets.
References (5)
- https://access.redhat.com/security/cve/CVE-2019-10221 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1732565 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10221 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10221
- https://www.cve.org/CVERecord?id=CVE-2019-10221
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-10221 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1732565 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10221 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10221 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-10221 |
Change history (0)
No recorded changes yet.