#6713 ipa: Insufficient permission check for ca-del, ca-disable and ca-enable commands (CVE-2017-2590)
Closed: fixed Opened by jcholast.

Multiple security issues were found in FreeIPA's 'ca' plugin. Any authenticated but unauthorised user can delete, disable or enable CAs in Dogtag. The impact in the deletion case is denial of service for cert issuance or OCSP signing, and deletion of secret keys. The impact for disablement is denial of service for cert issuance.


master:

  • b81ac59640f0b76fa9f53cf8be441f085a7089c4 ca: correctly authorise ca-del, ca-enable and ca-disable

ipa-4-4:

  • 1aa314c79648c442473f19344387bfe11ec2141b ca: correctly authorise ca-del, ca-enable and ca-disable

Metadata Update from @jcholast:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1413137
- Custom field tester adjusted to wanted

Metadata Update from @jcholast:
- Issue close_status updated to: fixed
- Issue set to the milestone: FreeIPA 4.4.4
- Issue status updated to: Closed (was: Open)

Metadata