Red Hat Bugzilla – Bug 826646
CVE-2012-2662 Certificate System: multiple XSS flaws
Last modified: 2018-01-30 13:05:11 EST
Multiple cross-site scripting issues were discovered in the Red Hat Certificate System's / Dogtag Certificate System's Agent and End Entity pages. An attacker could use these flaw to perform a cross-site scripting (XSS) attack against victims viewing Certificate System's web interface. The issue was originally reported via bug #814478. Following fixes were applied to address these issues: https://fedorahosted.org/pki/changeset/2411 https://fedorahosted.org/pki/changeset/2414 https://fedorahosted.org/pki/changeset/2417 https://fedorahosted.org/pki/changeset/2426
This issue has been addressed in following products: Red Hat Certificate System 8 Via RHSA-2012:1103 https://rhn.redhat.com/errata/RHSA-2012-1103.html
*** Bug 1221502 has been marked as a duplicate of this bug. ***
Statement: This issue affects the versions of pki-core as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2015:1347 https://rhn.redhat.com/errata/RHSA-2015-1347.html