CVE-2024-5906

Prisma Cloud Compute: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
16.3th percentile
Discovered by
Third party
Vendor-published field
Published
Jun 12, 2024
Assigned by palo_alto

Description

A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.

Weakness: CWE-79

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Cloud Cloud Security cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Prisma Cloud Compute
  • paloaltonetworks · prisma_cloud
  • paloaltonetworks · prisma_cloud — vendor states not affected

Credit

Palo Alto Networks thanks Tomasz Stachowicz for discovering and reporting this issue.

Vendor remediation

This issue is fixed in Prisma Cloud Compute 32.05 (O'Neal - Update 5) and all later versions.

Something wrong here?