Описание
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
Отчет
Rated Moderate because this is unauthenticated disclosure of internal host and topology metadata only; the disclosed hostnames and roles do not directly expose credentials or sensitive data, making this a reconnaissance/follow-on-attack enabler rather than a direct compromise.
Меры по смягчению последствий
Remove unnecessary version and topology details from the unauthenticated response.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Certificate System 9 | pki-core | Fix deferred | ||
| Red Hat Enterprise Linux 10 | dogtag-pki | Fix deferred | ||
| Red Hat Enterprise Linux 6 | pki-core | Out of support scope | ||
| Red Hat Enterprise Linux 7 | pki-core | Fix deferred | ||
| Red Hat Enterprise Linux 8 | pki-core | Fix deferred | ||
| Red Hat Enterprise Linux 9 | pki-core | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
An unauthenticated client can query the Security Domain hosts inventor ...
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
EPSS
5.3 Medium
CVSS3