Upstream information
Description
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
No SUSE Bugzilla entries cross referenced.SUSE Security Advisories:
- RHSA-2024:4222, published Tue Sep 10 14:32:27 UTC 2024
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Liberty Linux 7 LTSS |
| Patchnames: RHSA-2024:4222 |
SUSE Liberty Linux 9 |
| Patchnames: RHSA-2024:4165 |
SUSE Timeline for this CVE
CVE page created: Tue Jun 11 18:00:18 2024CVE page last modified: Thu Sep 26 13:42:23 2024