VYPR

pki-core

by Red Hat

CVEs (4)

  • CVE-2015-0234HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.01

    Multiple temporary file creation vulnerabilities in pki-core 10.2.0.

  • CVE-2020-1721MedApr 30, 2021
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim…

  • CVE-2022-2393MedJul 14, 2022
    risk 0.37cvss 5.7epss 0.00

    A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain,…

  • CVE-2019-10178MedMar 18, 2020
    risk 0.30cvss 4.6epss 0.01

    It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted…