CVE-2018-1080
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- dogtagpki/dogtagpki
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2018:1979Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1080Issue Tracking, Third Party Advisory
- https://pagure.io/freeipa/issue/7453Third Party Advisory
- https://review.gerrithub.io/c/dogtagpki/pki/+/404435Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1979Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1080Issue Tracking, Third Party Advisory
- https://pagure.io/freeipa/issue/7453Third Party Advisory
- https://review.gerrithub.io/c/dogtagpki/pki/+/404435Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.