Red Hat Bugzilla – Bug 1456030
CVE-2017-7509 certificate system 8: Enrolling certificate without certreq field causes CA to crash
Last modified: 2018-02-02 14:42:15 EST
When submitting for certificate enrollment, Google Chrome cuts off the certreq field in the submission. This causes a null pointer exception that causes the CA to crash. This can also be reproduced using Firefox by directly passing the request to the servelet without the certreq field.
Moved back to NEW since this is a CVE.
This issue has been addressed in the following products: Red Hat Certificate System 8 with Advanced Access Via RHSA-2017:2560 https://access.redhat.com/errata/RHSA-2017:2560