CVE-2020-1696: XSS
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-1696?
CVE-2020-1696 is a vulnerability found in all pki-core 10.x.x versions, allowing for Stored Cross-Site Scripting (XSS) attacks.
What is the severity of CVE-2020-1696?
The severity of CVE-2020-1696 is medium with a score of 5.4.
How does CVE-2020-1696 affect Redhat Certificate System?
Redhat Certificate System version 9.0 and 10.0 are affected by CVE-2020-1696.
How does CVE-2020-1696 affect Dogtagpki Dogtagpki?
Dogtagpki Dogtagpki versions 10.0 to 10.8.3 are affected by CVE-2020-1696.
How can I fix CVE-2020-1696?
To fix CVE-2020-1696, it is recommended to update to the latest version of pki-core.