CVEs (14)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted...Show more |
4Dogtagpki FedoraprojectOracle+1 more12Dogtagpki Enterprise LinuxEnterprise Linux Eus+9 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin p...Show more |
A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. T...Show more |
A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vul...Show more |
3Dogtagpki FedoraprojectRedhat4Certificate System DogtagpkiEnterprise Linux+1 moreJun 17, 2026 Mar 15, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat...Show more |
In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override...Show more |
2Dogtagpki Redhat2Certificate System DogtagpkiJun 17, 2026 Mar 31, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (...Show more |
2Dogtagpki Redhat2Certificate System DogtagpkiJun 17, 2026 Mar 20, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is...Show more |
2Dogtagpki Redhat2Dogtagpki Enterprise LinuxJun 17, 2026 Mar 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attack...Show more |
2Dogtagpki Redhat2Dogtagpki Enterprise LinuxJun 17, 2026 Mar 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vuln...Show more |
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick a...Show more |
2Dogtagpki Redhat2Dogtagpki Enterprise LinuxJun 17, 2026 Mar 18, 2020 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a...Show more |
2Dogtagpki Redhat4Dogtagpki Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular auth...Show more |
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow...Show more |