PT-2009-3230 · Red Hat · Red Hat Certificate System
Robert Mead
·
Published
2009-05-27
·
Updated
2009-06-09
·
CVE-2009-0588
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Certificate System versions 7.3
Description
The issue affects the Registration Authority (RA) component in Red Hat Certificate System, where the
agent/request/op.cgi component allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.Recommendations
For Red Hat Certificate System version 7.3, consider restricting access to the
agent/request/op.cgi component to prevent unauthorized approval of certificate requests. As a temporary workaround, limit the ability to modify the request ID field to authorized personnel only.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Certificate System