CVE-2020-1721: XSS
A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
Other sources
A flaw was found in the Key Recovery Authority (KRA) Agent Service where it did not properly sanitize the recovery ID during a key recovery request, enabling a Reflected Cross-Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
A flaw was found in the pki-kra package. A cross-site scripting issue in the key recover feature of the pki agent can be used to execute Javascript on the key recovery page.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-1721?
CVE-2020-1721 is a vulnerability in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5, which enables a reflected cross-site scripting (XSS) attack.
How severe is CVE-2020-1721?
CVE-2020-1721 has a severity rating of 6.1 (medium).
What is the affected software version of CVE-2020-1721?
The affected software version of CVE-2020-1721 is pki-core 10.10.5.
How can I fix CVE-2020-1721?
To fix CVE-2020-1721, update pki-core to version 10.10.5 or apply the appropriate patch according to the vendor's instructions.
Where can I find more information about CVE-2020-1721?
You can find more information about CVE-2020-1721 at the following references: [CVE.org](https://www.cve.org/CVERecord?id=CVE-2020-1721), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-1721), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1777579), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:0851).