PT-2018-10112 · Red Hat+1 · Dogtag Pki+2

Ftweedal

·

Published

2018-06-26

·

Updated

2019-10-09

·

CVE-2018-1080

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dogtag PKI versions prior to 10.6.2
Description The issue is related to the application of ACL allow and deny rules in certain configurations, causing these rules to be reversed. Specifically, when a server is set to process allow rules before deny rules, as defined by authz.evaluateOrder=allow,deny, the allow rules will incorrectly deny access, while the deny rules will grant access. This reversal may lead to unintended consequences, including potential escalation of privileges.
Recommendations For Dogtag PKI versions prior to 10.6.2, update to version 10.6.2 or later to resolve the issue. As a temporary workaround, consider changing the configuration to process deny rules before allow rules by setting authz.evaluateOrder=deny,allow until a patch is applied.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2018_1979
CVE-2018-1080
RHSA-2018:1979
RHSA-2018_1979

Affected Products

Centos
Dogtag Pki
Red Hat