Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5404

Опубликовано: 07 сент. 2016
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freeipa:freeipa:-:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*
cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00664
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 4.3
redhat
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
debian
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke cert ...

CVSS3: 6.5
github
около 3 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

oracle-oval
почти 9 лет назад

ELSA-2016-1797: ipa security update (MODERATE)

EPSS

Процентиль: 70%
0.00664
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284