Upstream information
Description
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
No SUSE Bugzilla entries cross referenced.SUSE Security Advisories:
- RHSA-2024:4222, published Tue Sep 10 14:32:27 UTC 2024
List of released packages
| Product(s) | Fixed package version(s) | References | 
|---|---|---|
| SUSE Liberty Linux 7 LTSS | 
 | Patchnames: RHSA-2024:4222 | 
| SUSE Liberty Linux 9 | 
 | Patchnames: RHSA-2024:4165 | 
SUSE Timeline for this CVE
CVE page created: Tue Jun 11 18:00:18 2024CVE page last modified: Wed Oct 1 15:06:22 2025
