Oval Definition:oval:com.redhat.rhsa:def:20204847
Revision Date:2020-11-04Version:636
Title:RHSA-2020:4847: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
Description:The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.

Security Fix(es):

  • jquery: Cross-site scripting via cross-domain ajax requests (CVE-2015-9251)

  • bootstrap: XSS in the data-target attribute (CVE-2016-10735)

  • bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute (CVE-2018-14040)

  • bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip (CVE-2018-14042)

  • bootstrap: XSS in the tooltip or popover data-template attribute (CVE-2019-8331)

  • jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)

  • jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)

  • jquery: Passing HTML containing
  • pki: Dogtag's python client does not validate certificates (CVE-2020-15720)

  • pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page (CVE-2019-10146)

  • pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab (CVE-2019-10179)

  • pki-core: Reflected XSS in getcookies?url= endpoint in CA (CVE-2019-10221)

  • pki-core: KRA vulnerable to reflected XSS via the getPk12 page (CVE-2020-1721)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-9251
    CVE-2016-10735
    CVE-2018-14040
    CVE-2018-14042
    CVE-2019-10146
    CVE-2019-10179
    CVE-2019-10221
    CVE-2019-11358
    CVE-2019-8331
    CVE-2020-11022
    CVE-2020-11023
    CVE-2020-15720
    CVE-2020-1721
    CVE-2020-1935
    CVE-2020-1938
    CVE-2020-25715
    CVE-2022-25762
    RHSA-2020:4847
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • Module pki-deps:10.6 is enabled
  • Module pki-core:10.6 is enabled
  • BACK