← Vulnerability feed

Vulnerability record · CVE-2019-10180 · published 31 March 2020

CVE-2019-10180: Dogtagpki cross-site scripting vulnerability

Dogtagpki · Dogtagpki

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

4.8 CVSS 3.1 Medium EPSS 0.74% · top 47.2% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score, v2 3.5
0.74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10180 Issue TrackingThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10180 Issue TrackingThird Party Advisory

Track CVE-2019-10180 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2021-20179Dogtagpki incorrect authorization vulnerabilityA flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …EPSS 1.2%8.1CVE-2018-1080Dogtagpki improper access control vulnerabilityDogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and…EPSS 1.5%7.8CVE-2021-3551Dogtagpki cleartext storage of sensitive data vulnerabilityA flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This …EPSS 0.19%7.5CVE-2022-2414Dogtag PKI XML parser allows XXE file disclosureDogtag PKI parses XML documents with external entity resolution enabled, exposing it to XML external entity (XXE) attacks. A remote attacker can send…EPSS 86%analysed7.5CVE-2017-7537Redhat enterprise linux desktop hard-coded credentials vulnerabilityIt was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4.…EPSS 1.5%7.5CVE-2013-1886Redhat certificate system vulnerabilityFormat string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System …EPSS 2.2%6.8CVE-2020-15720Dogtagpki improper certificate validation vulnerabilityIn Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter wa…EPSS 0.98%6.5CVE-2017-7509Redhat certificate system improper input validation vulnerabilityAn input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2019-10180), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.