Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Dogtag PKI 信任管理问题漏洞
Vulnerability Description
Dogtag PKI 10.8.3及之前版本中存在信任管理问题漏洞,该漏洞源于pki.client.PKIConnection类没有开启python请求的证书验证并且所有的请求函数都使用了硬编码的‘verify’参数。攻击者可利用该漏洞实施中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A