PT-2009-3230 · Red Hat · Red Hat Certificate System
Robert Mead
·
Publicado
2009-05-27
·
Atualizado
2009-06-09
·
CVE-2009-0588
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Certificate System versions 7.3
Description
The issue affects the Registration Authority (RA) component in Red Hat Certificate System, where the
agent/request/op.cgi component allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.Recommendations
For Red Hat Certificate System version 7.3, consider restricting access to the
agent/request/op.cgi component to prevent unauthorized approval of certificate requests. As a temporary workaround, limit the ability to modify the request ID field to authorized personnel only.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat Certificate System