Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update
🔗 CVE IDs covered (17)
📋 Description
CVE-2015-9251 — jquery: Cross-site scripting via cross-domain ajax requests CVE-2016-10735 — bootstrap: XSS in the data-target attribute CVE-2018-14040 — bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute CVE-2018-14042 — bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip CVE-2019-8331 — bootstrap: XSS in the tooltip or popover data-template attribute CVE-2019-10146 — pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page CVE-2019-10179 — pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab CVE-2019-10221 — pki-core: Reflected XSS in getcookies?url= endpoint in CA CVE-2019-11358 — jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection CVE-2020-1721 — pki-core: KRA vulnerable to reflected XSS via the getPk12 page CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability CVE-2020-11022 — jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods CVE-2020-15720 — pki: Dogtag's python client does not validate certificates CVE-2020-25715 — pki-core: XSS in the certificate search results CVE-2022-25762 — tomcat: request mixup
🔗 References (44)
- selfhttps://access.redhat.com/errata/RHSA-2020:4847
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1376706
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1399546
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1406505
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601614
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1666907
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1686454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1695901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1701972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1710171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1721684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1724433
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1732565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1732981
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1777579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1805541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1821851
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1822246
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1824939
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1824948
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1825998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1828406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1842734
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1842736
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1843537
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1845447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1850004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1855273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1855319
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856368
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857933
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1861911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1871064
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1873235
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4847.json