Vulnerabilities > Dogtagpki > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-03-18 CVE-2019-10146 Cross-site Scripting vulnerability in multiple products
A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page.
network
high complexity
redhat dogtagpki CWE-79
4.7
2018-07-03 CVE-2018-1080 Unspecified vulnerability in Dogtagpki
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed.
network
dogtagpki
6.8