CVE-2022-0020
10.02.2022, 18:15
A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.
Vendor | Product | Version |
---|---|---|
paloaltonetworks | cortex_xsoar | 6.1.0 |
paloaltonetworks | cortex_xsoar | 6.1.0:1016923 |
paloaltonetworks | cortex_xsoar | 6.1.0:1031903 |
paloaltonetworks | cortex_xsoar | 6.1.0:1077664 |
paloaltonetworks | cortex_xsoar | 6.1.0:1209934 |
paloaltonetworks | cortex_xsoar | 6.1.0:1271079 |
paloaltonetworks | cortex_xsoar | 6.1.0:848144 |
paloaltonetworks | cortex_xsoar | 6.2.0 |
paloaltonetworks | cortex_xsoar | 6.2.0:1271082 |
paloaltonetworks | cortex_xsoar | 6.2.0:1321594 |
paloaltonetworks | cortex_xsoar | 6.2.0:1473927 |
paloaltonetworks | cortex_xsoar | 6.2.0:1578666 |
paloaltonetworks | cortex_xsoar | 6.2.0:1822745 |
𝑥
= Vulnerable software versions
References