Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-5404

Опубликовано: 07 сент. 2016
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4
CVSS3: 6.5

Описание

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

РелизСтатусПримечание
artful

not-affected

4.4.3-3ubuntu2.1
bionic

not-affected

4.4.3-3ubuntu2.1
cosmic

not-affected

4.4.3-3ubuntu2.1
devel

not-affected

4.4.3-3ubuntu2.1
disco

not-affected

4.4.3-3ubuntu2.1
eoan

not-affected

4.4.3-3ubuntu2.1
esm-apps/bionic

not-affected

4.4.3-3ubuntu2.1
esm-apps/focal

not-affected

4.4.3-3ubuntu2.1
esm-apps/jammy

not-affected

4.4.3-3ubuntu2.1
esm-apps/xenial

released

4.3.1-0ubuntu1+esm1

Показывать по

EPSS

Процентиль: 70%
0.00664
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
nvd
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
debian
почти 9 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke cert ...

CVSS3: 6.5
github
около 3 лет назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

oracle-oval
почти 9 лет назад

ELSA-2016-1797: ipa security update (MODERATE)

EPSS

Процентиль: 70%
0.00664
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3