Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-66406

Опубликовано: 03 дек. 2025
Источник: redhat
CVSS3: 5

Описание

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is fixed in 0.29.0.

A flaw was found in Step CA, an online certificate authority. This vulnerability allows a highly privileged attacker to improperly revoke SSH certificates. Such unauthorized revocation can disrupt services, leading to a denial of service for systems configured with the SSHPOP provisioner that rely on these certificates for secure access.

Отчет

This vulnerability is rated Moderate because it allows a highly privileged attacker to improperly revoke SSH certificates in Step CA deployments configured with the SSHPOP provisioner, leading to a denial of service. This impacts Red Hat products utilizing Step CA with the SSHPOP provisioner.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2418682github.com/smallstep/certificates: Step CA: Denial of Service via improper SSH certificate revocation authorization

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
4 месяца назад

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is fixed in 0.29.0.

CVSS3: 5
github
4 месяца назад

step-ca Has Improper Authorization Check for SSH Certificate Revocation

5 Medium

CVSS3