CVE-2024-5906
Prisma Cloud Compute: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
16.3th percentile
Discovered by
Third party
Vendor-published field
Published
Jun 12, 2024
Assigned by palo_alto
Description
A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Cloud | Cloud Security | cna-assigner |
Vendor-reported products (3)
- Palo Alto Networks · Prisma Cloud Compute
- paloaltonetworks · prisma_cloud
- paloaltonetworks · prisma_cloud — vendor states not affected
Credit
Palo Alto Networks thanks Tomasz Stachowicz for discovering and reporting this issue.
Vendor remediation
This issue is fixed in Prisma Cloud Compute 32.05 (O'Neal - Update 5) and all later versions.