Description

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

INFO

Published Date :

2024-06-11T19:30:25.613Z

Last Modified :

2025-11-20T07:06:06.877Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2023-4727 vulnerability.

Vendors Products
Redhat
  • Certificate System Eus
  • Enterprise Linux
  • Rhel Aus
  • Rhel E4s
  • Rhel Eus
  • Rhel Tus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact