CVE-2019-10179: XSS
A flaw was found in recoveryID search field at KRA's DRM agent page in authorize recovery tab, this user input is not being sanitized and therefore it is vulnerable to a reflected XSS.
Other sources
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
It was found that the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-10179?
CVE-2019-10179 is a vulnerability in the Key Recovery Authority (KRA) Agent Service of pki-core 10.x.x versions.
What is the severity of CVE-2019-10179?
The severity of CVE-2019-10179 is medium (6.1).
How does CVE-2019-10179 work?
CVE-2019-10179 enables a Reflected Cross Site Scripting (XSS) vulnerability by not properly sanitizing the recovery request search page in the KRA Agent Service.
Which software versions are affected by CVE-2019-10179?
CVE-2019-10179 affects all pki-core 10.x.x versions, specifically 10.5.18-12.el7_9, 10.5.9-15.el7_6, and 10.5.16-7.el7_7.
How can I fix CVE-2019-10179?
To fix CVE-2019-10179, update pki-core to version 10.5.18-12.el7_9 or apply the necessary patches provided by Redhat.