A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4727.json",
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-305"
]
}[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"159929905925728052316151616387447793014",
"113095399420068434420381245555077035978",
"288783561434776018263235974094856668653",
"260411814325342437038561811612076220899",
"298691720800095042077601500153425280985",
"282899423113382899287314268677515942293",
"5592907713344490912007962262607983349",
"158901841031943750396144694674860046702",
"298691720800095042077601500153425280985",
"92982385441739889376753730948398713376",
"280365455956133149241511346987472086766",
"220755669660904726396283238114078783908"
],
"threshold": 0.9
},
"id": "CVE-2023-4727-08dbced1",
"target": {
"file": "base/server/src/main/java/com/netscape/cmscore/session/LDAPSecurityDomainSessionTable.java"
},
"source": "https://github.com/dogtagpki/pki/commit/54e5b3c5932ad634b5ddf5b1d4d88c9419d6f720",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 891.0,
"function_hash": "232994835997540767755135353028017056674"
},
"id": "CVE-2023-4727-0b7f747c",
"target": {
"function": "getStringValue",
"file": "base/server/src/main/java/com/netscape/cmscore/session/LDAPSecurityDomainSessionTable.java"
},
"source": "https://github.com/dogtagpki/pki/commit/aa7161ba378caf5cf0471aafb679a842679c8388",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"159929905925728052316151616387447793014",
"113095399420068434420381245555077035978",
"288783561434776018263235974094856668653",
"260411814325342437038561811612076220899",
"298691720800095042077601500153425280985",
"282899423113382899287314268677515942293",
"5592907713344490912007962262607983349",
"158901841031943750396144694674860046702",
"298691720800095042077601500153425280985",
"92982385441739889376753730948398713376",
"280365455956133149241511346987472086766",
"220755669660904726396283238114078783908"
],
"threshold": 0.9
},
"id": "CVE-2023-4727-3fb422af",
"target": {
"file": "base/server/src/main/java/com/netscape/cmscore/session/LDAPSecurityDomainSessionTable.java"
},
"source": "https://github.com/dogtagpki/pki/commit/aa7161ba378caf5cf0471aafb679a842679c8388",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 891.0,
"function_hash": "232994835997540767755135353028017056674"
},
"id": "CVE-2023-4727-634701ab",
"target": {
"function": "getStringValue",
"file": "base/server/src/main/java/com/netscape/cmscore/session/LDAPSecurityDomainSessionTable.java"
},
"source": "https://github.com/dogtagpki/pki/commit/54e5b3c5932ad634b5ddf5b1d4d88c9419d6f720",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 654.0,
"function_hash": "111222733731203503158836197018858573424"
},
"id": "CVE-2023-4727-66d12c05",
"target": {
"function": "sessionExists",
"file": "base/server/src/main/java/com/netscape/cmscore/session/LDAPSecurityDomainSessionTable.java"
},
"source": "https://github.com/dogtagpki/pki/commit/aa7161ba378caf5cf0471aafb679a842679c8388",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 654.0,
"function_hash": "111222733731203503158836197018858573424"
},
"id": "CVE-2023-4727-d4b8c163",
"target": {
"function": "sessionExists",
"file": "base/server/src/main/java/com/netscape/cmscore/session/LDAPSecurityDomainSessionTable.java"
},
"source": "https://github.com/dogtagpki/pki/commit/54e5b3c5932ad634b5ddf5b1d4d88c9419d6f720",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4727.json"
"2026-08-12T14:51:29Z"