REDHAT-BUG-2232218: High severity Dogtag Certificate Authority vulnerability
The token authentication scheme in Dogtag CA can be bypassed with a Ldap injection. By passing the query string parameter sessionID=, an attacker can authenticate with the existing session saved in Ldap directory server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2232218?
The severity of REDHAT-BUG-2232218 is categorized as a serious security vulnerability due to potential authentication bypass.
How can I mitigate REDHAT-BUG-2232218?
To mitigate REDHAT-BUG-2232218, it is recommended to update to the latest version of Dogtag Certificate Authority that addresses this vulnerability.
What is the primary impact of REDHAT-BUG-2232218?
The primary impact of REDHAT-BUG-2232218 is the ability for an attacker to bypass the token authentication scheme, compromising user sessions.
Is REDHAT-BUG-2232218 relevant for all versions of Dogtag CA?
REDHAT-BUG-2232218 affects specific versions of Dogtag Certificate Authority that implement the token authentication scheme.
What type of attack does REDHAT-BUG-2232218 involve?
REDHAT-BUG-2232218 involves an LDAP injection attack that exploits the query string parameter to authenticate unauthorized sessions.