Security Advisory

CVE-2019-10180

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-03-31 16:31:52
Last updated 2024-08-04 22:10:10
Assigner redhat
State PUBLISHED

Description

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.