Impact
Dogtag PKI’s ACME responder accepts any IP address literal as a DNS identifier when validating HTTP‑01 challenges and follows HTTP redirects without verifying that the new location is a public address. This flaw allows an unauthenticated ACME account owner to instruct the Dogtag server to send HTTP GET requests to arbitrary internal network services, a classic Server‑Side Request Forgery (CWE‑918). If the Dogtag instance uses the in‑memory database backend, the response body from the internal target is returned to the attacker in the ACME challenge error, exposing internal data.
Affected Systems
The affected systems are Red Hat Certificate System versions 9, 10 and 11, as well as Red Hat Enterprise Linux releases 6, 7, 8, 9 and 10. Any installation that includes the Dogtag PKI component and the ACME responder service is vulnerable.
Risk and Exploitability
The CVSS score of 5.8 places this issue in the medium severity range. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalogue. An attacker only needs to register an ACME account without prior authentication; no privileged credentials on the host are required. Because redirects are unchecked, the Dogtag server can reach any IP address, making internal data exposure high whenever the service can contact internal networks. With no immediate vendor patch or effective workaround, the risk remains medium to high until remediation is applied.
OpenCVE Enrichment