GHSA-rvm7-rc5g-c98qHighCVSS 7.5

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with...

Published
June 11, 2024
Last Modified
June 26, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

🔗 References (15)