Back to search
CVE-2016-5404
Published: Sep 7, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2016-f56c765d67
vendor-advisory
x_refsource_FEDORA
92525
vdb-entry
x_refsource_BID
[oss-security] 20160817 CVE-2016-5404 freeipa: Insufficient privileges check in certificate revocation
mailing-list
x_refsource_MLIST
FEDORA-2016-92a3655b70
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-7898627d08
vendor-advisory
x_refsource_FEDORA
RHSA-2016:1797
vendor-advisory
x_refsource_REDHAT
https://fedorahosted.org/freeipa/ticket/6232
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now