CVE Published: 26/07/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: redhat |
Vendor: MIT |
Product: krb5 Status : PUBLISHED
CVE-2017-7562 Description
An authentication bypass flaw was found in the way krb5\'s certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.