A flaw was found in dogtag-pki and... CVE-2023-4727

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息