PT-2009-3230 · Red Hat · Red Hat Certificate System

Robert Mead

·

Publicado

2009-05-27

·

Atualizado

2009-06-09

·

CVE-2009-0588

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Certificate System versions 7.3
Description The issue affects the Registration Authority (RA) component in Red Hat Certificate System, where the agent/request/op.cgi component allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.
Recommendations For Red Hat Certificate System version 7.3, consider restricting access to the agent/request/op.cgi component to prevent unauthorized approval of certificate requests. As a temporary workaround, limit the ability to modify the request ID field to authorized personnel only.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-0588
RHSA-2009:1065

Produtos afetados

Red Hat Certificate System