CVE Vulnerabilities

CVE-2017-2590

Published: Jul 27, 2018 | Modified: Oct 09, 2019
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Ubuntu
MEDIUM

A vulnerability was found in ipa before 4.4. IdMs ca-del, ca-disable, and ca-enable commands did not properly check the users permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.

Affected Software

Name Vendor Start Version End Version
Freeipa Freeipa * 4.4.0 (excluding)
Red Hat Enterprise Linux 7 RedHat ipa-0:4.4.0-14.el7_3.6 *
Freeipa Ubuntu artful *
Freeipa Ubuntu precise *
Freeipa Ubuntu upstream *
Freeipa Ubuntu yakkety *
Freeipa Ubuntu zesty *

References