PT-2020-14607 · Red Hat+2 · Dogtag Pki+3

Published

2020-07-14

·

Updated

2020-11-04

·

CVE-2020-15720

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dogtag PKI versions prior to 10.9.0-b1
Description The issue concerns the pki.client.PKIConnection class in Dogtag PKI, which did not enable python-requests certificate validation. This was due to the verify parameter being hard-coded in all request functions, making it impossible to override the setting. As a result, tools using this class may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases.
Recommendations For Dogtag PKI versions prior to 10.9.0-b1, update to version 10.9.0-b1 or later to resolve the issue.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2020_4847
CVE-2020-15720
RHSA-2020:4847
RHSA-2020_4847
RLSA-2020:4847

Affected Products

Centos
Dogtag Pki
Red Hat
Rocky Linux