VYPR
Medium severity4.3NVD Advisory· Published Mar 20, 2020· Updated Jun 17, 2026

CVE-2019-10179

CVE-2019-10179

Description

A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:dogtagpki:dogtagpki:*:*:*:*:*:*:*:*
    Range: >=10.0,<=10.8.3
  • cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • pki-core/pki-coredescription
  • Range: 10.x.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.