A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
CVSS
No CVSS.
References
Configurations
No configuration.
History
09 Jul 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Jul 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Jul 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Jul 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Jun 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Jun 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Jun 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Jun 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-11 20:15
Updated : 2024-07-09 12:15
NVD link : CVE-2023-4727
Mitre link : CVE-2023-4727
JSON object : View
Products Affected
No product.
CWE
CWE-305
Authentication Bypass by Primary Weakness