A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web interface. Prisma Cloud Compute SaaS versions were automatically upgraded to the fixed release. No additional action is required for these instances. This issue impacts: Prisma Cloud Compute 20.12 versions earlier than Prisma Cloud Compute 20.12.552; Prisma Cloud Compute 21.04 versions earlier than Prisma Cloud Compute 21.04.439.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://security.paloaltonetworks.com/CVE-2021-3043 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: palo_alto
Published: 2021-07-15T16:45:13.845939Z
Updated: 2024-09-17T01:21:53.231Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-3043
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-07-15T17:15:08.793
Modified: 2024-11-21T06:20:49.830
Link: CVE-2021-3043
Redhat
No data.