CVE-2023-4727
HIGH EPSS 46.9%
Published Jun 11, 20242y ago · Modified Jun 26, 20264d ago
7.5 CVSS 3.1
Published Jun 11, 2024 2y ago
Last Modified Jun 26, 2026 4d ago
Description
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector Adjacent
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
46.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-305
References 14
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4051
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4070
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4164
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4165
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4179
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4222
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4367
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4403
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:4413
- access.redhat.com https://access.redhat.com/security/cve/CVE-2023-4727
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2232218
- github.com https://github.com/advisories/GHSA-rvm7-rc5g-c98q
- github.com https://github.com/dogtagpki/pki/commit/54e5b3c5932ad634b5ddf5b1d4d88c9419d6f720
- github.com https://github.com/dogtagpki/pki/commit/aa7161ba378caf5cf0471aafb679a842679c8388
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.