pki-core
by Red Hat
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-0234 | Hig | 0.49 | 7.5 | 0.01 | Aug 29, 2017 | Multiple temporary file creation vulnerabilities in pki-core 10.2.0. | ||
| CVE-2020-1721 | Med | 0.40 | 6.1 | 0.01 | Apr 30, 2021 | A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim… | ||
| CVE-2022-2393 | Med | 0.37 | 5.7 | 0.00 | Jul 14, 2022 | A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain,… | ||
| CVE-2019-10178 | Med | 0.30 | 4.6 | 0.01 | Mar 18, 2020 | It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted… |
- risk 0.49cvss 7.5epss 0.01
Multiple temporary file creation vulnerabilities in pki-core 10.2.0.
- risk 0.40cvss 6.1epss 0.01
A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim…
- risk 0.37cvss 5.7epss 0.00
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain,…
- risk 0.30cvss 4.6epss 0.01
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted…