CVE-2013-1885
published 2014-01-24CVE-2013-1885: Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.24%
65.8th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | certificate_system | — | — |
| redhat | dogtag_certificate_system | — | — |
| redhat | dogtag_certificate_system | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r743-88qv-qhcg: Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8
ghsa_unreviewed·2022-05-17
CVE-2013-1885 [MEDIUM] CWE-79 GHSA-r743-88qv-qhcg: Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8
Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.
Red Hat
System: pki-tps XSS flaw
vendor_redhat·2013-05-22·CVSS 4.3
CVE-2013-1885 [MEDIUM] CWE-79 System: pki-tps XSS flaw
System: pki-tps XSS flaw
Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [fedora-all]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-1885 [MEDIUM] CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [fedora-all]
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple s
Bugzilla
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [epel-5]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-1885 [MEDIUM] CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [epel-5]
CVE-2013-1885 CVE-2013-1886 pki-tps various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for pki-tps: see bloc
Bugzilla
CVE-2013-1885 Certificate System: pki-tps XSS flaw
bugzilla·2013-03-19·CVSS 4.3
CVE-2013-1885 [MEDIUM] CVE-2013-1885 Certificate System: pki-tps XSS flaw
CVE-2013-1885 Certificate System: pki-tps XSS flaw
It was reported that Certificate System suffers from XSS flaws in the /tus/ and /tus/tus/ URLs, such as:
GET /tus/tus/%22%2b%61%6c%65%72%74%28%34%38%32%36%37%29%2b%22
or
GET /tus/%22%2b%61%6c%65%72%74%28%36%31%34%35%32%29%2b%22
which will in turn output something like:
<!--
var uriBase = "/tus/"+alert(85384)+";
var userid = "admin";
This was reported against Certificate System 8.1 and may also affect Dogtag 9 and 10.
Discussion:
Created pki-tps tracking bugs for this issue
Affects: fedora-all [bug 966189]
Affects: epel-5 [bug 966190]
---
This issue has been addressed in following products:
Red Hat Certificate System 8
Via RHSA-2013:0856 https://rhn.redhat.com/errata/RHSA-2013-0856.html
---
pki-tps-9.0.11-1.fc17 has been p
http://osvdb.org/93626http://osvdb.org/93627http://rhn.redhat.com/errata/RHSA-2013-0856.htmlhttp://www.securitytracker.com/id/1029685https://bugzilla.redhat.com/show_bug.cgi?id=923039https://exchange.xforce.ibmcloud.com/vulnerabilities/84477http://osvdb.org/93626http://osvdb.org/93627http://rhn.redhat.com/errata/RHSA-2013-0856.htmlhttp://www.securitytracker.com/id/1029685https://bugzilla.redhat.com/show_bug.cgi?id=923039https://exchange.xforce.ibmcloud.com/vulnerabilities/84477
2014-01-24
Published