CVE-2019-10180
31.03.2020, 17:15
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
| Vendor | Product | Version |
|---|---|---|
| dogtagpki | dogtagpki | 10.0 ≤ 𝑥 ≤ 10.8.3 |
| redhat | certificate_system | 10.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases