CVE-2019-10221: XSS
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.
Other sources
A Reflected Cross Site Scripting vulnerability was found in the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.
A vulnerability, reflected cross site scripting in getcookies?url= endpoint in CA was reported in pki-core
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-10221.
What is the severity level of CVE-2019-10221?
The severity level of CVE-2019-10221 is medium.
How does CVE-2019-10221 affect the pki-core server?
CVE-2019-10221 affects the pki-core server by allowing an attacker to execute reflected cross-site scripting attacks.
Which versions of pki-core are affected by CVE-2019-10221?
All pki-core 10.x.x versions are affected by CVE-2019-10221.
How can I fix the CVE-2019-10221 vulnerability?
To fix the CVE-2019-10221 vulnerability, you should update pki-core to version 10.9.0 or apply the appropriate patches provided by Redhat.