It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing certificates.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-16550 | It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing certificates. |
Ubuntu USN |
USN-7146-1 | Dogtag PKI vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T16:04:11.958Z
Reserved: 2017-04-05T00:00:00.000Z
Link: CVE-2017-7537
No data.
Status : Modified
Published: 2018-07-26T13:29:00.340
Modified: 2024-11-21T03:32:06.593
Link: CVE-2017-7537
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN