Dogtag PKI is a designed enterprise software system manage enterprise Public Key Infrastructure deployments.
Security Fix(es):
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.(CVE-2023-4727)
{ "severity": "High" }
{ "x86_64": [ "pki-core-debuginfo-11.0.0-6.oe2203sp3.x86_64.rpm", "pki-core-debugsource-11.0.0-6.oe2203sp3.x86_64.rpm", "pki-symkey-11.0.0-6.oe2203sp3.x86_64.rpm", "pki-tools-11.0.0-6.oe2203sp3.x86_64.rpm", "pki-tps-11.0.0-6.oe2203sp3.x86_64.rpm" ], "aarch64": [ "pki-core-debuginfo-11.0.0-6.oe2203sp3.aarch64.rpm", "pki-core-debugsource-11.0.0-6.oe2203sp3.aarch64.rpm", "pki-symkey-11.0.0-6.oe2203sp3.aarch64.rpm", "pki-tools-11.0.0-6.oe2203sp3.aarch64.rpm", "pki-tps-11.0.0-6.oe2203sp3.aarch64.rpm" ], "noarch": [ "pki-base-11.0.0-6.oe2203sp3.noarch.rpm", "pki-base-java-11.0.0-6.oe2203sp3.noarch.rpm", "pki-ca-11.0.0-6.oe2203sp3.noarch.rpm", "pki-help-11.0.0-6.oe2203sp3.noarch.rpm", "pki-kra-11.0.0-6.oe2203sp3.noarch.rpm", "pki-ocsp-11.0.0-6.oe2203sp3.noarch.rpm", "pki-server-11.0.0-6.oe2203sp3.noarch.rpm", "pki-tks-11.0.0-6.oe2203sp3.noarch.rpm", "python3-pki-11.0.0-6.oe2203sp3.noarch.rpm" ], "src": [ "pki-core-11.0.0-6.oe2203sp3.src.rpm" ] }