First published: Wed Sep 07 2016(Updated: )
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Freeipa Freeipa | ||
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Fedoraproject Fedora | =23 | |
Fedoraproject Fedora | =24 | |
Fedoraproject Fedora | =25 |
https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=cf74584d0f772f3f5eccc1d30c001e4212a104fd
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.