CVE-2019-10179

A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10179 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:dogtagpki:dogtagpki:*:*:*:*:*:*:*:*

History

12 Feb 2023, 23:33

Type Values Removed Values Added
Summary It was found that the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code. A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2021:0975', 'name': 'https://access.redhat.com/errata/RHSA-2021:0975', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1695901', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1695901', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2021:0819', 'name': 'https://access.redhat.com/errata/RHSA-2021:0819', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2020:4847', 'name': 'https://access.redhat.com/errata/RHSA-2020:4847', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2019-10179', 'name': 'https://access.redhat.com/security/cve/CVE-2019-10179', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2021:0851', 'name': 'https://access.redhat.com/errata/RHSA-2021:0851', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 16:18

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2021:0975 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1695901 -
  • (MISC) https://access.redhat.com/errata/RHSA-2021:0819 -
  • (MISC) https://access.redhat.com/errata/RHSA-2020:4847 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2019-10179 -
  • (MISC) https://access.redhat.com/errata/RHSA-2021:0851 -
Summary A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code. It was found that the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.

Information

Published : 2020-03-20 15:15

Updated : 2023-12-10 13:27


NVD link : CVE-2019-10179

Mitre link : CVE-2019-10179

CVE.ORG link : CVE-2019-10179


JSON object : View

Products Affected

redhat

  • enterprise_linux

dogtagpki

  • dogtagpki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')