PT-2020-14607 · Red Hat+2 · Dogtag Pki+3
Published
2020-07-14
·
Updated
2020-11-04
·
CVE-2020-15720
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dogtag PKI versions prior to 10.9.0-b1
Description
The issue concerns the pki.client.PKIConnection class in Dogtag PKI, which did not enable python-requests certificate validation. This was due to the verify parameter being hard-coded in all request functions, making it impossible to override the setting. As a result, tools using this class may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases.
Recommendations
For Dogtag PKI versions prior to 10.9.0-b1, update to version 10.9.0-b1 or later to resolve the issue.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Dogtag Pki
Red Hat
Rocky Linux