REDHAT-BUG-488706: Medium severity Red Hat Certificate System vulnerability
Robert Mead reported that the Registration Authority component (rhpki-ra) of the Red Hat Certificate System / Dogtag Certificate System did not properly check agent's authorizations in some CGI scripts.
In deployments, where certificate requests are processed by multiple agent groups, agent from any group was able to approve or reject certificate requests in the queue for any other agent group, if he was able to guess request ID.
Original report: bug #484828
Affected systems: Dogtag Certificate System Red Hat Certificate System 7.3
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-488706?
REDHAT-BUG-488706 is classified as a medium severity vulnerability due to improper authorization checks.
How do I fix REDHAT-BUG-488706?
To mitigate REDHAT-BUG-488706, you should update to the latest version of the affected Red Hat Certificate System or Dogtag Certificate System as per Red Hat's security advisories.
What components are affected by REDHAT-BUG-488706?
The vulnerability affects the Registration Authority component of the Red Hat Certificate System and Dogtag Certificate System.
Can REDHAT-BUG-488706 lead to unauthorized access?
Yes, REDHAT-BUG-488706 can potentially allow unauthorized actions due to the lack of proper authorization checks in CGI scripts.
Who reported the REDHAT-BUG-488706 vulnerability?
The REDHAT-BUG-488706 vulnerability was reported by Robert Mead.