VYPR

Pki

by Dogtag

Source repositories

CVEs (4)

  • CVE-2021-20179HigMar 15, 2021
    risk 0.46cvss 8.1epss 0.01

    A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and…

  • CVE-2023-4727HigJun 11, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to…

  • CVE-2026-17039LowJul 24, 2026
    risk 0.13cvss 3.1epss 0.00

    A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to…

  • CVE-2022-2414HigJul 29, 2022
    risk 0.07cvss 7.5epss 0.86

    Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.