Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5404

Опубликовано: 07 сент. 2016
Источник: debian
EPSS Низкий

Описание

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freeipafixed4.3.2-5package

Примечания

  • https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=cf74584d0f772f3f5eccc1d30c001e4212a104fd (master)

  • https://fedorahosted.org/freeipa/ticket/6232

EPSS

Процентиль: 70%
0.00664
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 4.3
redhat
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
nvd
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
github
около 3 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

oracle-oval
почти 9 лет назад

ELSA-2016-1797: ipa security update (MODERATE)

EPSS

Процентиль: 70%
0.00664
Низкий