CVE-2017-2590
Last modified
CVE-2017-2590 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.
Metrics
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freeipa | Freeipa | < 4.4.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.3 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- http://rhn.redhat.com/errata/RHSA-2017-0388.htmlThird Party Advisory
- http://www.securityfocus.com/bid/96557Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2590Issue Tracking, Patch
- http://rhn.redhat.com/errata/RHSA-2017-0388.htmlThird Party Advisory
- http://www.securityfocus.com/bid/96557Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2590Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2590?
How severe is CVE-2017-2590?
How do I fix CVE-2017-2590?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-2584arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 all…
- CVE-2017-2585Red Hat Keycloak before version 2.5.1 has an implementation …
- CVE-2017-2586A null pointer dereference vulnerability was found in netpbm…3.3
- CVE-2017-2587A memory allocation vulnerability was found in netpbm before…3.3
- CVE-2017-2588Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-2589It was discovered that the hawtio servlet 1.4 uses a single …8.7
- CVE-2017-2591389-ds-base before version 1.3.6 is vulnerable to an imprope…3.7
- CVE-2017-2592python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1…5.9
- CVE-2017-2593Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-2594hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2…5.4
- CVE-2017-2595It was found that the log file viewer in Red Hat JBoss Enter…7.7
- CVE-2017-2596The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in…
Are you affected by CVE-2017-2590?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
