CVE-2020-1696
published 2020-03-20CVE-2020-1696: A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.76%
51.4th percentile
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dogtag-pki | — | — |
| dogtagpki | dogtagpki | 10.0 – 10.8.3 | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pki-core: Stored XSS in TPS profile creation
vendor_redhat·2020-02-03·CVSS 4.6
CVE-2020-1696 [MEDIUM] CWE-79 pki-core: Stored XSS in TPS profile creation
pki-core: Stored XSS in TPS profile creation
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
A flaw was found in the pki-core's Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
Package: pki-core (Red Hat Certificate System 10) - Affected
Debian
CVE-2020-1696: dogtag-pki - A flaw was found in the all pki-core 10.x.x versions, where Token Processing Ser...
vendor_debian·2020·CVSS 4.6
CVE-2020-1696 [MEDIUM] CVE-2020-1696: dogtag-pki - A flaw was found in the all pki-core 10.x.x versions, where Token Processing Ser...
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
Scope: local
bullseye: open
GHSA
GHSA-59m3-5f56-55x8: A flaw was found in the all pki-core 10
ghsa_unreviewed·2022-05-24
CVE-2020-1696 [LOW] CWE-79 GHSA-59m3-5f56-55x8: A flaw was found in the all pki-core 10
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
OSV
CVE-2020-1696: A flaw was found in the all pki-core 10
osv·2020-03-20·CVSS 5.4
CVE-2020-1696 [MEDIUM] CVE-2020-1696: A flaw was found in the all pki-core 10
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [fedora-all]
bugzilla·2020-02-04·CVSS 4.6
CVE-2020-1696 [MEDIUM] CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [fedora-all]
CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2020-1696 pki-core: Stored XSS in TPS profile creation
bugzilla·2019-12-06·CVSS 4.6
CVE-2020-1696 [MEDIUM] CVE-2020-1696 pki-core: Stored XSS in TPS profile creation
CVE-2020-1696 pki-core: Stored XSS in TPS profile creation
A flaw was found in Profile ID field while adding new profile at TPS's web page, when adding new profile (Profile ID) input field not getting filtered or sanitize the specially crafted javascript like alert(document.domain) and being stored/triggered everytime with domain name in response. This user input is not being sanitized and therefore it is vulnerable to a Stored XSS.
Discussion:
Acknowledgments:
Name: Pritam Singh (Red Hat)
---
Created pki-core tracking bugs for this issue:
Affects: fedora-all [bug 1797988]
---
Do you know if this was reported in the upstream issue tracker and there is a fix?
---
Upstream is aware. There is currently no fix. I will check for upstream issue tracker.
However, the security conseque
Bugzilla
CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS
bugzilla·2019-06-17·CVSS 2.4
CVE-2019-10180 [LOW] CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS
CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS
A vulnerability was found in pki-tps web UI, in the table showing tokens.
Several fields including the User ID and the policy are not sanitized and could be set or modified by an attacker, in order to launch a Stored Cross Site Scripting (XSS) attack.
The XSS will be triggered each time the malicious token is shown in the authenticated victim's web browser when navigating to the vulnerable URL.
Discussion:
Acknowledgments:
Name: Pritam Singh (Red Hat)
---
Reducing the severity to Low : the attacker needs to be able to modify the token policies in order to store the javascript code. This requires high privileges.
---
Created pki-core tracking bugs for this issue:
Affects: fedora-all [bug 1798080]
Bugzilla
CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab
bugzilla·2019-06-10·CVSS 4.6
CVE-2019-10178 [MEDIUM] CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab
CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab
A vulnerability was found in pki-tps. An stored XSS when adding a new token in TPS's web page Activity tab due to an improper sanitization of the token id input.
Discussion:
Acknowledgments:
Name: Pritam Singh (Red Hat)
---
Created pki-core tracking bugs for this issue:
Affects: fedora-all [bug 1798388]
---
Do you know if this was reported upstream and there is an upstream fix?
---
In reply to comment #10:
> Do you know if this was reported upstream and there is an upstream fix?
Correcting the need info.
Regards
Yogendra.
---
Upstream is aware. There is currently no fix.
However, the security consequences are very limited.
e.g. : Thanks to the webUI using client side TLS authentication
2020-03-20
Published