Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1080

Опубликовано: 03 июл. 2018
Источник: nvd
CVSS3: 7.5
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dogtagpki:dogtagpki:*:*:*:*:*:*:*:*
Версия до 10.6.1 (включая)

EPSS

Процентиль: 63%
0.00458
Низкий

7.5 High

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.

CVSS3: 7.5
redhat
больше 7 лет назад

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.

CVSS3: 7.5
debian
больше 7 лет назад

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.j ...

CVSS3: 8.1
github
больше 3 лет назад

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.

oracle-oval
больше 7 лет назад

ELSA-2018-1979: pki-core security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 63%
0.00458
Низкий

7.5 High

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-noinfo