CVE-2019-10146: XSS
A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.
Other sources
A Reflected Cross Site Scripting flaw was found in the pki-ca module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.
A Reflected Cross Site Scripting flaw was found in the pki-ca module from the pki-core server.
In the /ca/agent/ca/profileProcess form, the basicConstraintsPathLen parameter is not properly sanitized by the server and could allow an attacker to inject a specially crafted value that will be executed on the victim's browser.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-10146?
CVE-2019-10146 is a Reflected Cross Site Scripting (XSS) vulnerability found in the pki-ca module from the pki-core server.
What is the severity of CVE-2019-10146?
The severity of CVE-2019-10146 is medium with a CVSS score of 4.7.
How does CVE-2019-10146 work?
The vulnerability in the pki-core server allows an attacker to inject a specially crafted value that will be executed on the victim's browser, resulting in a Cross Site Scripting attack.
Which versions of pki-core are affected by CVE-2019-10146?
All versions of pki-core 10.x.x are affected, including versions 10.5.18-12.el7_9, 10.5.9-15.el7_6, and 10.5.16-7.el7_7.
How can I fix CVE-2019-10146?
To fix CVE-2019-10146, update pki-core to version 10.5.18-12.el7_9, 10.5.9-15.el7_6, or 10.5.16-7.el7_7.