Описание
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
Отчет
Exploitation of this flaw requires an existing CA-Administrator-equivalent account; it is not exploitable by an anonymous or unprivileged user on its own. This precondition is already reflected in the CVSS vector via Privileges Required: High. The integrated Dogtag certificate authority is enabled by default in a standard ipa-server-install deployment, and certificate profile import is a routine, expected CA Administrator operation. Once that precondition is met, exploitation is deterministic and reaches full code execution as pkiuser, with further escalation to root observed in tested environments. On its own, this flaw provides a privilege-escalation path from CA Administrator to host-level code execution
Меры по смягчению последствий
Until a fixed package is available, restrict membership in CA Administrator and equivalent roles to fully trusted operators, and audit certificate profile import operations for unexpected or unrecognized profile content. Review any custom ExternalProcessConstraint executable configuration in Dogtag for unnecessary exposure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Certificate System 9 | pki-core | Affected | ||
| Red Hat Enterprise Linux 10 | dogtag-pki | Affected | ||
| Red Hat Enterprise Linux 6 | pki-core | Out of support scope | ||
| Red Hat Enterprise Linux 7 | pki-core | Affected | ||
| Red Hat Enterprise Linux 8 | pki-core | Affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/pki-core | Affected | ||
| Red Hat Enterprise Linux 9 | pki-core | Affected |
Показывать по
Дополнительная информация
Статус:
7.2 High
CVSS3
Связанные уязвимости
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate autho ...
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
7.2 High
CVSS3