cbcvebase.
CVE-2016-5404
published 2016-09-07

CVE-2016-5404: The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary…

medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianfreeipa< freeipa 4.3.2-5 (bookworm)freeipa 4.3.2-5 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
freeipafreeipa>= 0 < 4.3.2-54.3.2-5
freeipafreeipa>= 0 < 4.3.2-54.3.2-5
freeipafreeipa>= 0 < 4.3.2-54.3.2-5
freeipafreeipa>= 0 < 3.3.4-0ubuntu3.1+esm13.3.4-0ubuntu3.1+esm1
freeipafreeipa>= 0 < 4.3.1-0ubuntu1+esm14.3.1-0ubuntu1+esm1
oraclelinux
oraclelinux

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM