Логотип exploitDog
bind:"CVE-2023-4727"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-4727"

Количество 11

Количество 11

ubuntu логотип

CVE-2023-4727

около 1 года назад

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-4727

около 1 года назад

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-4727

около 1 года назад

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-4727

около 1 года назад

A flaw was found in dogtag-pki and pki-core. The token authentication ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250109-02

5 месяцев назад

Уязвимость pki-server

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2024:4165

12 месяцев назад

Important: pki-core security update

EPSS: Низкий
github логотип

GHSA-rvm7-rc5g-c98q

около 1 года назад

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-4367

12 месяцев назад

ELSA-2024-4367: pki-core security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4222

12 месяцев назад

ELSA-2024-4222: pki-core security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4165

12 месяцев назад

ELSA-2024-4165: pki-core security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-00342

около 1 года назад

Уязвимость пакетов dogtag-pki и pki-core, связанная с обходом аутентификации в силу исходной ошибки, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-4727

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
0%
Низкий
около 1 года назад
redhat логотип
CVE-2023-4727

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2023-4727

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2023-4727

A flaw was found in dogtag-pki and pki-core. The token authentication ...

CVSS3: 7.5
0%
Низкий
около 1 года назад
redos логотип
ROS-20250109-02

Уязвимость pki-server

CVSS3: 7.5
0%
Низкий
5 месяцев назад
rocky логотип
RLSA-2024:4165

Important: pki-core security update

0%
Низкий
12 месяцев назад
github логотип
GHSA-rvm7-rc5g-c98q

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

CVSS3: 7.5
0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-4367

ELSA-2024-4367: pki-core security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2024-4222

ELSA-2024-4222: pki-core security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2024-4165

ELSA-2024-4165: pki-core security update (IMPORTANT)

12 месяцев назад
fstec логотип
BDU:2025-00342

Уязвимость пакетов dogtag-pki и pki-core, связанная с обходом аутентификации в силу исходной ошибки, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу