CVE Vulnerabilities

CVE-2018-1080

Published: Jul 03, 2018 | Modified: Oct 09, 2019
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.

Affected Software

Name Vendor Start Version End Version
Dogtagpki Dogtagpki * 10.6.1 (including)
Dogtag-pki Ubuntu artful *
Dogtag-pki Ubuntu esm-apps/xenial *
Dogtag-pki Ubuntu upstream *
Dogtag-pki Ubuntu xenial *
Red Hat Enterprise Linux 7 RedHat pki-core-0:10.5.1-13.1.el7_5 *

References