在 Dogtag PKI(pki-core)中发现了一个漏洞。CMCAuthForEST 身份验证插件在未通过基本认证(BasicAuth)提交包含终端用户 TLS 客户端证书的 EST fullcmc 注册请求时,会错误地允许访问(fail open)。此时,SSL_CLIENT_CERT 会话属性仍保留 EST 子系统的代理证书,导致下游授权检查将该请求误认为是具有代理特权的请求。经过身份验证的 EST 用户可以利用此漏洞,获取由 CA 签名的、具有任意主题名称的证书。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Certificate System 10 | any |
affected |
| Red Hat | Red Hat Certificate System 11 | any |
affected |
| Red Hat | Red Hat Certificate System 9 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Certificate System 10 | - |
cpe:/a:redhat:certificate_system:10
|
|
| Red Hat | Red Hat Certificate System 11 | - |
cpe:/a:redhat:certificate_system:11
|
|
| Red Hat | Red Hat Certificate System 9 | - |
cpe:/a:redhat:certificate_system:9
|
|
| Red Hat | Red Hat Certificate System 9 | - |
cpe:/a:redhat:certificate_system:9
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet