Total vulnerabilities in the database
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
Software | From | Fixed in |
---|---|---|
redhat / enterprise_linux | 7.0 | 7.0.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
dogtagpki / dogtagpki | 10.0 | 10.8.3.x |