CVE-2022-2393
published 2022-07-14CVE-2022-2393: A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw…
medium5.7CVSS 3.1
AVAACLPRLUINSUCHINAN
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dogtag-pki | — | — |
| pki-core_project | pki-core | <= 10.12.4 | — |
| pki-core_project | pki-core | — | — |
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.7MEDIUM
GHSA
GHSA-hjh3-jq28-5qcc: A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled
ghsa_unreviewed·2022-07-15
CVE-2022-2393 [MEDIUM] CWE-285 GHSA-hjh3-jq28-5qcc: A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.
OSV
CVE-2022-2393: A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled
osv·2022-07-14·CVSS 5.7
CVE-2022-2393 [MEDIUM] CVE-2022-2393: A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.
Red Hat
kernel: sfc: fix considering that all channels have TX queues
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49378 [MEDIUM] kernel: sfc: fix considering that all channels have TX queues
kernel: sfc: fix considering that all channels have TX queues
In the Linux kernel, the following vulnerability has been resolved:
sfc: fix considering that all channels have TX queues
Normally, all channels have RX and TX queues, but this is not true if
modparam efx_separate_tx_channels=1 is used. In that cases, some
channels only have RX queues and others only TX queues (or more
preciselly, they have them allocated, but not initialized).
Fix efx_channel_has_tx_queues to return the correct value for this case
too.
Messages shown at probe time before the fix:
sfc 0000:03:00.0 ens6f0np0: MC command 0x82 inlen 544 failed rc=-22 (raw=0) arg=0
------------[ cut here ]------------
netdevice: ens6f0np0: failed to initialise TXQ -1
WARNING: CPU: 1 PID: 626 at drivers/net/ethernet/sfc/ef10.c:2393
Red Hat
pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field
vendor_redhat·2022-07-12·CVSS 5.7
CVE-2022-2393 [MEDIUM] CWE-287 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field
pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content
Debian
CVE-2022-2393: dogtag-pki - A flaw was found in pki-core, which could allow a user to get a certificate for ...
vendor_debian·2022·CVSS 5.7
CVE-2022-2393 [MEDIUM] CVE-2022-2393: dogtag-pki - A flaw was found in pki-core, which could allow a user to get a certificate for ...
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.
Scope: local
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-14
Published