CVE-2012-3367
Summary
| CVE | CVE-2012-3367 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-13 20:55:00 UTC |
| Updated | 2017-08-29 01:31:00 UTC |
| Description | Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate. |
Risk And Classification
Problem Types: CWE-310
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Certificate System | 7.1 | All | All | All |
| Application | Redhat | Certificate System | 7.2 | All | All | All |
| Application | Redhat | Certificate System | 7.3 | All | All | All |
| Application | Redhat | Certificate System | 8 | All | All | All |
| Application | Redhat | Certificate System | 8.0 | All | All | All |
| Application | Redhat | Certificate System | 7.1 | All | All | All |
| Application | Redhat | Certificate System | 7.2 | All | All | All |
| Application | Redhat | Certificate System | 7.3 | All | All | All |
| Application | Redhat | Certificate System | 8 | All | All | All |
| Application | Redhat | Certificate System | 8.0 | All | All | All |
| Application | Redhat | Certificate System | All | All | All | All |
| Application | Redhat | Dogtag Certificate System | All | All | All | All |
| Application | Redhat | Dogtag Certificate System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Certificate System Multiple Cross Site Scripting and Security Bypass Vulnerabilities | BID | www.securityfocus.com | |
| Overview - dogtagpki - Pagure.io | CONFIRM | fedorahosted.org | Exploit, Patch |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Security Advisory SA50013 - Red Hat Certificate System Cross-Site Scripting and Security Bypass Vulnerabilities - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 836268 – (CVE-2012-3367) CVE-2012-3367 Certificate System: CA certificate can be revoked | CONFIRM | bugzilla.redhat.com | |
| 84098 | OSVDB | osvdb.org | |
| Red Hat Certificate System Bugs Let Remote Users Conduct Cross-Site Scripting and Denial of Service Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.