CVE-2019-10178: XSS
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10178?
CVE-2019-10178 is a vulnerability found in the Token Processing Service (TPS) that enables a Stored Cross Site Scripting (XSS) attack.
How does the CVE-2019-10178 vulnerability work?
The vulnerability occurs due to the Token Processing Service (TPS) not properly sanitizing the Token IDs from the 'Activity' page, allowing an unauthenticated attacker to execute XSS attacks.
What is the severity of CVE-2019-10178?
The severity of CVE-2019-10178 is medium with a CVSS score of 6.1.
What software is affected by CVE-2019-10178?
The Dogtagpki software is affected by CVE-2019-10178.
How can CVE-2019-10178 be fixed?
To fix CVE-2019-10178, it is recommended to update to the latest version of the Dogtagpki software.