Impact
The vulnerability in Dogtag PKI, used by FreeIPA’s certificate authority, allows an authenticated user with CA Administrator privileges to import a certificate profile containing unsanitized content. The ExternalProcessConstraint component of Dogtag executes provided data without fully validating it, enabling the attacker to run arbitrary commands with environment variables controlled by the attacker, executed as the pkiuser account. This results in implementation of a command‑injection flaw (CWE‑78). The consequence is code execution that could be leveraged to expand the attacker’s foothold within the system, depending on the privileges of the pkiuser account.
Affected Systems
The affected products are Red Hat Certificate System 9 and several Red Hat Enterprise Linux releases (6, 7, 8, 9, 10). Any deployment of Dogtag PKI that includes the certprofile‑import functionality and allows CA Administrator roles to import profiles is vulnerable. Custom configurations of ExternalProcessConstraint that reference executable programs also pose an elevated risk.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, which suggests the public exploitation potential may be lower. Nevertheless, the attack vector requires authentication as a CA Administrator so the attack is limited to privileged users. If a privileged user mistakenly imports a malicious profile or an attacker gains CA Administrator credentials, arbitrary commands can be run as pkiuser without further authentication. This raises the integrity and confidentiality of the system to a significant threat level.
OpenCVE Enrichment