Red Hat / Certificate System
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-2393 | pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field | HIGH | 7.6 | Jul 14, 2022 |
| CVE-2021-20179 | pki-core: Unprivileged users can renew any certificate | HIGH | 8.1 | Mar 15, 2021 |
| CVE-2019-10180 | pki-core: unsanitized token parameters in TPS resulting in stored XSS | MEDIUM | 4.8 | Mar 31, 2020 |
| CVE-2020-1696 | pki-core: Stored XSS in TPS profile creation | MEDIUM | 5.4 | Mar 20, 2020 |
| CVE-2017-7509 | 8: Enrolling certificate without certreq field causes CA to crash | MEDIUM | 6.5 | Jul 26, 2018 |
| CVE-2013-1886 | System: pki-tps format string injection | HIGH | 7.5 | Jan 24, 2014 |
| CVE-2013-1885 | System: pki-tps XSS flaw | MEDIUM | 4.3 | Jan 24, 2014 |
| CVE-2012-4556 | pki-tps: Connection reset when performing empty certificate search in TPS | MEDIUM | 4.0 | Jan 4, 2013 |
| CVE-2012-4555 | pki-tps: Temporary denial of service on interrupted token format operations | MEDIUM | 4.0 | Jan 4, 2013 |
| CVE-2012-4543 | System: Multiple cross-site scripting flaws by displaying CRL or processing profile | MEDIUM | 4.3 | Jan 4, 2013 |
| CVE-2012-3367 | System: CA certificate can be revoked | MEDIUM | 5.5 | Aug 13, 2012 |
| CVE-2012-2662 | System: multiple XSS flaws | MEDIUM | 4.3 | Aug 13, 2012 |
| CVE-2010-3869 | System: SCEP one-time PIN reuse | MEDIUM | 4.0 | Nov 17, 2010 |
| CVE-2010-3868 | System: unauthenticated user can request SCEP one-time PIN decryption | MEDIUM | 5.8 | Nov 17, 2010 |
| CVE-2009-0588 | rhpki-ra: improper authorization checks in Cerificate System's Registration Authority | MEDIUM | 6.5 | May 27, 2009 |
| CVE-2008-5082 | System: missing public key challenge proof verification in the TPS component | MEDIUM | 6.0 | Jan 30, 2009 |
| CVE-2008-2368 | System: plain text passwords stored in debug log | LOW | 2.1 | Jan 20, 2009 |
| CVE-2008-2367 | System: insecure config file permissions | LOW | 2.1 | Jan 20, 2009 |
Showing 1 to 18 of 18 CVEs