Loading
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
Use CWE-79, Redhat vendor hub and Enterprise Linux product page to widen CVE-2019-10179 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-28369, CVE-2026-28368 and CVE-2026-35091 for nearby disclosures in the same product family.