Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15720

Опубликовано: 14 июл. 2020
Источник: nvd
CVSS3: 6.8
CVSS2: 4
EPSS Низкий

Описание

In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dogtagpki:dogtagpki:*:*:*:*:*:*:*:*
Версия до 10.8.3 (включая)

EPSS

Процентиль: 41%
0.00186
Низкий

6.8 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 6.8
ubuntu
почти 5 лет назад

In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.

CVSS3: 6.8
redhat
почти 5 лет назад

In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.

CVSS3: 6.8
debian
почти 5 лет назад

In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did n ...

github
около 3 лет назад

In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.

oracle-oval
больше 4 лет назад

ELSA-2020-4847: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 41%
0.00186
Низкий

6.8 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-295