A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2590 | Issue Tracking Patch |
http://www.securityfocus.com/bid/96557 | Third Party Advisory VDB Entry |
http://rhn.redhat.com/errata/RHSA-2017-0388.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2018-07-27 11:29
Updated : 2019-10-09 16:26
NVD link : CVE-2017-2590
Mitre link : CVE-2017-2590
JSON object : View
CWE
CWE-275
Permission Issues
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux
- enterprise_linux_server_aus
- enterprise_linux_workstation
- enterprise_linux_server_eus
- enterprise_linux_server
freeipa
- freeipa