The cert_revoke command in FreeIPA does not check for the...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 10, 2023
Description
Published by the National Vulnerability Database
Sep 7, 2016
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 10, 2023
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
References