CVE-2016-5404

MEDIUM

Freeipa - Improper Access Control

Title source: rule

Description

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

Scores

CVSS v3 6.5
EPSS 0.0066
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-284
Status published

Affected Products (7)

freeipa/freeipa
oracle/linux
oracle/linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
n/a/n/a

Timeline

Published Sep 07, 2016
Tracked Since Feb 18, 2026