CVE Published: 11/06/2024 |
CVE Updated: 21/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Certificate System 10.4 EUS for RHEL-8 Status : PUBLISHED
CVE-2023-4727 Description
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.