1 results (0.001 seconds)
CVSS: 7.5EPSS: 0%CPEs: 17EXPL: 0
CVE-2023-4727 – Ca: token authentication bypass vulnerability
https://notcve.org/view.php?id=CVE-2023-4727
11 Jun 2024 — A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege. Se encontró una falla en dogtag-pki y pki-core. El esquema de autenticación de token se puede omitir con una inyección LDAP. • https://access.redhat.com/errata/RHSA-2024:4051 • CWE-305: Authentication Bypass by Primary Weakness •