Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5404

Опубликовано: 17 авг. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

An insufficient permission check issue was found in the way IPA server treats certificate revocation requests. An attacker logged in with the 'retrieve certificate' permission enabled could use this flaw to revoke certificates, possibly triggering a denial of service attack.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1351593ipa: Insufficient privileges check in certificate revocation

EPSS

Процентиль: 70%
0.00664
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
nvd
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
debian
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke cert ...

CVSS3: 6.5
github
около 3 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

oracle-oval
почти 9 лет назад

ELSA-2016-1797: ipa security update (MODERATE)

EPSS

Процентиль: 70%
0.00664
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2