Bug 488706 (CVE-2009-0588)

Summary: CVE-2009-0588 rhpki-ra: improper authorization checks in Cerificate System's Registration Authority
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: alee, bstein, ckannan, kevinu, kseifried, mharmsen, security-response-team, shaines
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-10-25 19:54:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 484828, 488716    
Bug Blocks:    

Description Tomas Hoger 2009-03-05 11:19:43 UTC
Robert Mead reported that the Registration Authority component (rhpki-ra) of the Red Hat Certificate System / Dogtag Certificate System did not properly check agent's authorizations in some CGI scripts.

In deployments, where certificate requests are processed by multiple agent groups, agent from any group was able to approve or reject certificate requests in the queue for any other agent group, if he was able to guess request ID.

Original report: bug #484828

Affected systems:
Dogtag Certificate System
Red Hat Certificate System 7.3

Comment 2 Tomas Hoger 2009-05-14 18:23:33 UTC
Upstream SVN commit:
  svn diff -c 377 https://pki.fedoraproject.org/svn/pki/trunk/pki

Comment 3 errata-xmlrpc 2009-05-26 17:13:45 UTC
This issue has been addressed in following products:

  Red Hat Certificate System 7.3

Via RHSA-2009:1065 https://rhn.redhat.com/errata/RHSA-2009-1065.html