Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat FreeIPA 访问控制错误漏洞
Vulnerability Description
Red Hat FreeIPA是美国红帽(Red Hat)公司的一套集成的安全信息管理解决方案。该产品主要为Linux和Unix计算机网络提供身份管理、策略管理和审计管理(IPA)等功能。 Red Hat FreeIPA存在访问控制错误漏洞,该漏洞源于程序没有检查‘revoke certificate’权限。远程攻击者可借助‘retrieve certificate’权限利用该漏洞撤销任意证书。
CVSS Information
N/A
Vulnerability Type
N/A