Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53682

Опубликовано: 01 сент. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.

Отчет

Rated Moderate because this is unauthenticated disclosure of internal host and topology metadata only; the disclosed hostnames and roles do not directly expose credentials or sensitive data, making this a reconnaissance/follow-on-attack enabler rather than a direct compromise.

Меры по смягчению последствий

Remove unnecessary version and topology details from the unauthenticated response.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 9pki-coreFix deferred
Red Hat Enterprise Linux 10dogtag-pkiFix deferred
Red Hat Enterprise Linux 6pki-coreOut of support scope
Red Hat Enterprise Linux 7pki-coreFix deferred
Red Hat Enterprise Linux 8pki-coreFix deferred
Red Hat Enterprise Linux 9pki-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2487511pki-core: dogtag-pki: Unauthenticated Dogtag CA REST API exposes Security Domain Hosts

EPSS

Процентиль: 3%
0.0013
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 дня назад

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.

CVSS3: 5.3
nvd
5 дней назад

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.

CVSS3: 5.3
debian
5 дней назад

An unauthenticated client can query the Security Domain hosts inventor ...

CVSS3: 5.3
github
5 дней назад

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.

EPSS

Процентиль: 3%
0.0013
Низкий

5.3 Medium

CVSS3