Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq46-23h4-vfpj

Опубликовано: 24 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

EPSS

Процентиль: 12%
0.00211
Низкий

3.1 Low

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 3.1
ubuntu
24 дня назад

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

CVSS3: 3.1
redhat
25 дней назад

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

CVSS3: 3.1
nvd
24 дня назад

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

CVSS3: 3.1
debian
24 дня назад

A flaw was found in pki-core. The certificate authority (CA) renewal r ...

EPSS

Процентиль: 12%
0.00211
Низкий

3.1 Low

CVSS3

Дефекты

CWE-863