dogtagpki是Dogtagpki团队开源的一套证书管理软件系统。 Dogtag PKI存在授权问题漏洞,该漏洞源于web.xml安全约束使用精确URL模式匹配,通过添加尾随斜杠绕过Tomcat身份验证约束,可能导致未经身份验证的攻击者切换ACME服务状态,包括持久拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Certificate System 10 | any |
affected |
| Red Hat | Red Hat Certificate System 11 | any |
affected |
| Red Hat | Red Hat Certificate System 9 | any |
unknown |
any |
unknown | ||
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Certificate System 10 | - |
cpe:/a:redhat:certificate_system:10
|
|
| Red Hat | Red Hat Certificate System 11 | - |
cpe:/a:redhat:certificate_system:11
|
|
| Red Hat | Red Hat Certificate System 9 | - |
cpe:/a:redhat:certificate_system:9
|
|
| Red Hat | Red Hat Certificate System 9 | - |
cpe:/a:redhat:certificate_system:9
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49332 | 8.5 HIGH | Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity |
| CVE-2026-18107 | 7.8 HIGH | Criu: criu: container escape via rseq critical section hijack during checkpoint/restore |
| CVE-2026-16313 | 7.6 HIGH | Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq -- |
| CVE-2026-17072 | 3.3 LOW | Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_fla |
No comments yet