CVE-2019-10180
published 2020-03-31CVE-2019-10180: A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the…
PriorityP419medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.74%
50.4th percentile
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dogtag-pki | — | — |
| dogtagpki | dogtagpki | 10.0 – 10.8.3 | — |
| redhat | certificate_system | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv4.8MEDIUM
vendor_debian2.4LOW
vendor_redhat2.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pki-core: unsanitized token parameters in TPS resulting in stored XSS
vendor_redhat·2020-02-03·CVSS 2.4
CVE-2019-10180 [LOW] CWE-79 pki-core: unsanitized token parameters in TPS resulting in stored XSS
pki-core: unsanitized token parameters in TPS resulting in stored XSS
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
It was found that the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code
Debian
CVE-2019-10180: dogtag-pki - A vulnerability was found in all pki-core 10.x.x version, where the Token Proces...
vendor_debian·2019·CVSS 2.4
CVE-2019-10180 [LOW] CVE-2019-10180: dogtag-pki - A vulnerability was found in all pki-core 10.x.x version, where the Token Proces...
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
Scope: local
bullseye: open
GHSA
GHSA-3r6g-5p5v-m39h: A vulnerability was found in all pki-core 10
ghsa_unreviewed·2022-05-24
CVE-2019-10180 [LOW] CWE-79 GHSA-3r6g-5p5v-m39h: A vulnerability was found in all pki-core 10
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
OSV
CVE-2019-10180: A vulnerability was found in all pki-core 10
osv·2020-03-31·CVSS 4.8
CVE-2019-10180 [MEDIUM] CVE-2019-10180: A vulnerability was found in all pki-core 10
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [fedora-all]
bugzilla·2020-02-04·CVSS 2.4
CVE-2019-10180 [LOW] CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [fedora-all]
CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2020-1696 pki-core: Stored XSS in TPS profile creation
bugzilla·2019-12-06·CVSS 4.6
CVE-2020-1696 [MEDIUM] CVE-2020-1696 pki-core: Stored XSS in TPS profile creation
CVE-2020-1696 pki-core: Stored XSS in TPS profile creation
A flaw was found in Profile ID field while adding new profile at TPS's web page, when adding new profile (Profile ID) input field not getting filtered or sanitize the specially crafted javascript like alert(document.domain) and being stored/triggered everytime with domain name in response. This user input is not being sanitized and therefore it is vulnerable to a Stored XSS.
Discussion:
Acknowledgments:
Name: Pritam Singh (Red Hat)
---
Created pki-core tracking bugs for this issue:
Affects: fedora-all [bug 1797988]
---
Do you know if this was reported in the upstream issue tracker and there is a fix?
---
Upstream is aware. There is currently no fix. I will check for upstream issue tracker.
However, the security conseque
Bugzilla
CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS
bugzilla·2019-06-17·CVSS 2.4
CVE-2019-10180 [LOW] CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS
CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS
A vulnerability was found in pki-tps web UI, in the table showing tokens.
Several fields including the User ID and the policy are not sanitized and could be set or modified by an attacker, in order to launch a Stored Cross Site Scripting (XSS) attack.
The XSS will be triggered each time the malicious token is shown in the authenticated victim's web browser when navigating to the vulnerable URL.
Discussion:
Acknowledgments:
Name: Pritam Singh (Red Hat)
---
Reducing the severity to Low : the attacker needs to be able to modify the token policies in order to store the javascript code. This requires high privileges.
---
Created pki-core tracking bugs for this issue:
Affects: fedora-all [bug 1798080]
Bugzilla
CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab
bugzilla·2019-06-10·CVSS 4.6
CVE-2019-10178 [MEDIUM] CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab
CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab
A vulnerability was found in pki-tps. An stored XSS when adding a new token in TPS's web page Activity tab due to an improper sanitization of the token id input.
Discussion:
Acknowledgments:
Name: Pritam Singh (Red Hat)
---
Created pki-core tracking bugs for this issue:
Affects: fedora-all [bug 1798388]
---
Do you know if this was reported upstream and there is an upstream fix?
---
In reply to comment #10:
> Do you know if this was reported upstream and there is an upstream fix?
Correcting the need info.
Regards
Yogendra.
---
Upstream is aware. There is currently no fix.
However, the security consequences are very limited.
e.g. : Thanks to the webUI using client side TLS authentication
2020-03-31
Published