Impact
An unauthenticated REST endpoint (GET /ca/rest/securityDomain/hosts) in the Red Hat PKI Certificate System exposes a structured inventory of internal PKI/CA hosts, roles, and topology. An attacker can read this response without authentication or session, revealing the mapping of the internal public‑key infrastructure, the components that participate in certificate issuance, and the relationships between them. This information can be used to plan subsequent attacks, such as targeting specific CA services, crafting tailored credential‑spoilage payloads, or identifying privileged subsystems within the organization. The vulnerability is essentially an information‑disclosure flaw.
Affected Systems
Affected products are Red Hat Certificate System 9 and the Red Hat Enterprise Linux family (RHEL 6, 7, 8, 9, 10). The precise versions are listed by the CNA as 6 through 10 for RHEL and version 9 for the Certificate System.
Risk and Exploitability
The CVSS score of 5.3 places this in the medium severity range; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unsophisticated: an unauthenticated user can issue an HTTP GET request to the exposed endpoint from any network that can reach the PKI service. Because no authentication is required and the information is presented verbatim, exploitation does not require privileged credentials or additional preprocessing.
OpenCVE Enrichment