Bug 488706 (CVE-2009-0588) - CVE-2009-0588 rhpki-ra: improper authorization checks in Cerificate System's Registration Authority
Summary: CVE-2009-0588 rhpki-ra: improper authorization checks in Cerificate System's ...
Alias: CVE-2009-0588
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 484828 488716
TreeView+ depends on / blocked
Reported: 2009-03-05 11:19 UTC by Tomas Hoger
Modified: 2019-09-29 12:29 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2011-10-25 19:54:05 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:1065 0 normal SHIPPED_LIVE Moderate: rhpki-ra security update 2009-05-26 17:13:42 UTC

Description Tomas Hoger 2009-03-05 11:19:43 UTC
Robert Mead reported that the Registration Authority component (rhpki-ra) of the Red Hat Certificate System / Dogtag Certificate System did not properly check agent's authorizations in some CGI scripts.

In deployments, where certificate requests are processed by multiple agent groups, agent from any group was able to approve or reject certificate requests in the queue for any other agent group, if he was able to guess request ID.

Original report: bug #484828

Affected systems:
Dogtag Certificate System
Red Hat Certificate System 7.3

Comment 2 Tomas Hoger 2009-05-14 18:23:33 UTC
Upstream SVN commit:
  svn diff -c 377 https://pki.fedoraproject.org/svn/pki/trunk/pki

Comment 3 errata-xmlrpc 2009-05-26 17:13:45 UTC
This issue has been addressed in following products:

  Red Hat Certificate System 7.3

Via RHSA-2009:1065 https://rhn.redhat.com/errata/RHSA-2009-1065.html

Note You need to log in before you can comment on or make changes to this bug.