First published: Tue Jun 23 2020(Updated: )
A flaw was found in PKI, where the dogtag's pki.client.PKIConnection class disables the python-requests certificate validation. This flaw allows an attacker to intercept a connection between a FreeIPA client and a server, and execute an active Man-in-the-Middle attack. The highest threat from this vulnerability is to confidentiality and integrity.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dogtagpki Dogtagpki | <=10.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15720 is a vulnerability found in Dogtag PKI.
CVE-2020-15720 has a severity score of 6.8 (medium).
CVE-2020-15720 affects Dogtag PKI versions up to 10.8.3.
To fix CVE-2020-15720, update Dogtag PKI to version 10.9.0 or later.
You can find more information about CVE-2020-15720 at the following references: 1. [CVE-2020-15720 on CVE.org](https://www.cve.org/CVERecord?id=CVE-2020-15720) 2. [CVE-2020-15720 on NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-15720) 3. [Bugzilla Bug Report](https://bugzilla.redhat.com/show_bug.cgi?id=1855273) 4. [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2020:4847)