PT-2009-3230 · Red Hat · Red Hat Certificate System

Robert Mead

·

Published

2009-05-27

·

Updated

2009-06-09

·

CVE-2009-0588

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Certificate System versions 7.3
Description The issue affects the Registration Authority (RA) component in Red Hat Certificate System, where the agent/request/op.cgi component allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.
Recommendations For Red Hat Certificate System version 7.3, consider restricting access to the agent/request/op.cgi component to prevent unauthorized approval of certificate requests. As a temporary workaround, limit the ability to modify the request ID field to authorized personnel only.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-0588
RHSA-2009:1065

Affected Products

Red Hat Certificate System