Search CVE reports


Toggle filters

11 – 17 of 17 results


CVE-2019-10221

Low priority
Vulnerable

A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could...

1 affected package

dogtag-pki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dogtag-pki Not in release Not affected Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2019-10179

Low priority
Vulnerable

A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability....

1 affected package

dogtag-pki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dogtag-pki Not in release Not affected Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2019-10178

Low priority
Vulnerable

It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an...

1 affected package

dogtag-pki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dogtag-pki Not in release Not affected Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2019-10146

Low priority
Vulnerable

A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially...

1 affected package

dogtag-pki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dogtag-pki Not in release Not affected Vulnerable Vulnerable Needs evaluation
Show less packages

CVE-2017-7537

Medium priority

Some fixes available 1 of 3

It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication...

1 affected package

dogtag-pki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dogtag-pki Not in release Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-1080

Medium priority
Ignored

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow...

1 affected package

dogtag-pki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dogtag-pki Not in release Not affected Not affected Not affected Ignored
Show less packages

CVE-2015-0234

Negligible priority
Ignored

Multiple temporary file creation vulnerabilities in pki-core 10.2.0.

1 affected package

dogtag-pki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dogtag-pki Ignored Ignored
Show less packages