Dogtag PKI is a designed enterprise software system manage enterprise Public Key Infrastructure deployments.
Security Fix(es):
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.(CVE-2023-4727)
{
"severity": "High"
}{
"x86_64": [
"pki-core-debuginfo-11.0.0-8.oe2403.x86_64.rpm",
"pki-core-debugsource-11.0.0-8.oe2403.x86_64.rpm",
"pki-symkey-11.0.0-8.oe2403.x86_64.rpm",
"pki-tools-11.0.0-8.oe2403.x86_64.rpm",
"pki-tps-11.0.0-8.oe2403.x86_64.rpm"
],
"src": [
"pki-core-11.0.0-8.oe2403.src.rpm"
],
"aarch64": [
"pki-core-debuginfo-11.0.0-8.oe2403.aarch64.rpm",
"pki-core-debugsource-11.0.0-8.oe2403.aarch64.rpm",
"pki-symkey-11.0.0-8.oe2403.aarch64.rpm",
"pki-tools-11.0.0-8.oe2403.aarch64.rpm",
"pki-tps-11.0.0-8.oe2403.aarch64.rpm"
],
"noarch": [
"pki-base-11.0.0-8.oe2403.noarch.rpm",
"pki-base-java-11.0.0-8.oe2403.noarch.rpm",
"pki-ca-11.0.0-8.oe2403.noarch.rpm",
"pki-help-11.0.0-8.oe2403.noarch.rpm",
"pki-kra-11.0.0-8.oe2403.noarch.rpm",
"pki-ocsp-11.0.0-8.oe2403.noarch.rpm",
"pki-server-11.0.0-8.oe2403.noarch.rpm",
"pki-tks-11.0.0-8.oe2403.noarch.rpm",
"python3-pki-11.0.0-8.oe2403.noarch.rpm"
]
}