Palo Alto Networks Cortex Xsoar是美国Palo Alto Networks公司的一个安全编排自动化和响应 (Soar) 平台。 Palo Alto Network Cortex XSOAR 存在跨站脚本漏洞,该漏洞允许攻击者存储一个持久的javascript利用代码,导致在Cortex XSOAR web界面中执行任意操作。以下产品及版本受到影响:所有版本的Cortex XSOAR 6.1.0;Cortex XSOAR build 1958888之前的6.2.0builds。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Cortex XSOAR | 6.5.0 all | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-0016 | 7.4 HIGH | GlobalProtect App: Privilege Escalation Vulnerability When Using Connect Before Logon |
| CVE-2022-0017 | 7.0 HIGH | GlobalProtect App: Improper Link Resolution Vulnerability Leads to Local Privilege Escalat |
| CVE-2022-0011 | 6.5 MEDIUM | PAN-OS: URL Category Exceptions Match More URLs Than Intended in URL Filtering |
| CVE-2022-0018 | 6.1 MEDIUM | GlobalProtect App: Information Exposure Vulnerability When Connecting to GlobalProtect Por |
| CVE-2022-0019 | 4.7 MEDIUM | GlobalProtect App: Insufficiently Protected Credentials Vulnerability on Linux |
| CVE-2022-0021 | 3.3 LOW | GlobalProtect App: Information Exposure Vulnerability When Using Connect Before Logon |
No comments yet