Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2024.7146.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-7146-1)
Summary:The remote host is missing an update for the 'dogtag-pki' package(s) announced via the USN-7146-1 advisory.
Description:Summary:
The remote host is missing an update for the 'dogtag-pki' package(s) announced via the USN-7146-1 advisory.

Vulnerability Insight:
Christina Fu discovered that Dogtag PKI accidentally enabled a mock
authentication plugin by default. An attacker could potentially use
this flaw to bypass the regular authentication process and trick the
CA server into issuing certificates. This issue only affected Ubuntu
16.04 LTS. (CVE-2017-7537)

It was discovered that Dogtag PKI did not properly sanitize user
input. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 22.04 LTS. (CVE-2020-25715)

It was discovered that the XML parser did not properly handle entity
expansion. A remote attacker could potentially retrieve the content of
arbitrary files by sending specially crafted HTTP requests. This issue
only affected Ubuntu 16.04 LTS. (CVE-2022-2414)

Affected Software/OS:
'dogtag-pki' package(s) on Ubuntu 16.04, Ubuntu 22.04.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-7537
RHSA-2017:2335
https://access.redhat.com/errata/RHSA-2017:2335
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7537
https://github.com/dogtagpki/pki/commit/876d13c6d20e7e1235b9
Common Vulnerability Exposure (CVE) ID: CVE-2020-25715
https://bugzilla.redhat.com/show_bug.cgi?id=1891016
Common Vulnerability Exposure (CVE) ID: CVE-2022-2414
https://github.com/dogtagpki/pki/pull/4021
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.