CVE-2019-10146: Dogtagpki
Medium severity, CVSS 4.7. EPSS: 0.7% chance of exploitation in the next 30 days.
A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.
Affected products
- Dogtagpki Dogtagpki: from 10.0, up to and including 10.7.3
- Red Hat Enterprise Linux: version 7.0 only
Published 2020-03-18. Last modified 2026-06-17.