CVE-2021-3043Cross-site Scripting in Palo Alto Networks Prisma Cloud Compute

Severity
4.8MEDIUMNVD
CNA7.5
EPSS
0.2%
top 55.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 27

Description

A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web interface. Prisma Cloud Compute SaaS versions were automatically upgraded to the fixed release. No additional action is required for these instances. This issue impacts: Prisma Cloud Compute 20.12 versions earlier than Prisma Cloud Compute 20.1

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages3 packages

CVEListV5palo_alto_networks/prisma_cloud_compute21.0421.04.439+1
NVDpaloaltonetworks/prisma_cloud20.1220.12.552+1

🔴Vulnerability Details

2
GHSA
GHSA-789j-5m28-p6v3: A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrar2022-05-24
CVEList
Prisma Cloud: Cross-Site Scripting (XSS) Vulnerability in Prisma Cloud Compute Web Console2021-07-15

📋Vendor Advisories

1
Palo Alto
Prisma Cloud: Cross-Site Scripting (XSS) Vulnerability in Prisma Cloud Compute Web Console2021-07-14

💬Community

1
Bugzilla
CVE-2021-47555 kernel: net: vlan: fix underflow for the real_dev refcnt2024-05-27
CVE-2021-3043 — Cross-site Scripting in Palo | cvebase