Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxm7-22wp-69jx

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

EPSS

Процентиль: 56%
0.00341
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 4.3
redhat
около 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
nvd
около 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
debian
около 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke cert ...

oracle-oval
около 9 лет назад

ELSA-2016-1797: ipa security update (MODERATE)

EPSS

Процентиль: 56%
0.00341
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284