VYPR
Vendor

Pki Core Project

Products
1
CVEs
10
Across products
10
Status
Private

Products

1

Recent CVEs

10
  • CVE-2018-1080HigJul 3, 2018
    risk 0.49cvss 7.5epss 0.02

    Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny),…

  • CVE-2015-0234HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.01

    Multiple temporary file creation vulnerabilities in pki-core 10.2.0.

  • CVE-2020-25715MedMay 28, 2021
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data…

  • CVE-2022-2393MedJul 14, 2022
    risk 0.37cvss 5.7epss 0.00

    A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain,…

  • CVE-2019-10146MedMar 18, 2020
    risk 0.31cvss 4.7epss 0.01

    A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the…

  • CVE-2020-1696MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.01

    A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could…

  • CVE-2019-10178MedMar 18, 2020
    risk 0.30cvss 4.6epss 0.01

    It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted…

  • CVE-2019-10221MedMar 20, 2020
    risk 0.28cvss 4.3epss 0.01

    A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user…

  • CVE-2019-10179MedMar 20, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim…

  • CVE-2019-10180LowMar 31, 2020
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the…