pki-core: Stored XSS in TPS profile creation
Published Mar 20, 2020
5.4
MEDIUMCVSS 3.1
EPSS 0.76%
Description
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
Affected products
- Vendor n/a Product Pki-Core Defaultunknown
Affected
- all pki-core 10.x.x versions
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Pki-Core | unknown | Affected
|
Configuration 1
- 9.0
- 10.0
No data.
Red Hat Certificate System 9.4 EUS
idm-console-framework-0:1.1.17-4.el7dsrv
Fixed · RHSA-2021:0948
Red Hat Certificate System 9.4 EUS
pki-console-0:10.5.9-2.el7pki
Fixed · RHSA-2021:0948
Red Hat Certificate System 9.4 EUS
pki-core-0:10.5.9-15.el7pki
Fixed · RHSA-2021:0948
Red Hat Certificate System 9.4 EUS
redhat-pki-theme-0:10.5.9-5.el7pki
Fixed · RHSA-2021:0948
Red Hat Certificate System 9.7
pki-core-0:10.5.18-12.el7pki
Fixed · RHSA-2021:0947
Red Hat Certificate System 9.7
redhat-pki-theme-0:10.5.18-5.el7pki
Fixed · RHSA-2021:0947
Red Hat Certificate System 10
pki-core
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Certificate System 9.4 EUS | idm-console-framework-0:1.1.17-4.el7dsrv | Fixed | RHSA-2021:0948 |
| Red Hat Certificate System 9.4 EUS | pki-console-0:10.5.9-2.el7pki | Fixed | RHSA-2021:0948 |
| Red Hat Certificate System 9.4 EUS | pki-core-0:10.5.9-15.el7pki | Fixed | RHSA-2021:0948 |
| Red Hat Certificate System 9.4 EUS | redhat-pki-theme-0:10.5.9-5.el7pki | Fixed | RHSA-2021:0948 |
| Red Hat Certificate System 9.7 | pki-core-0:10.5.18-12.el7pki | Fixed | RHSA-2021:0947 |
| Red Hat Certificate System 9.7 | redhat-pki-theme-0:10.5.18-5.el7pki | Fixed | RHSA-2021:0947 |
| Red Hat Certificate System 10 | pki-core | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2020-1696 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1780707 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1696 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12554 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1696
- https://www.cve.org/CVERecord?id=CVE-2020-1696
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-1696 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1780707 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1696 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12554 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-1696 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-1696 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data