LDAP injection in PKI - CVE-2023-4727

 

LDAP injection in PKI - CVE-2023-4727

Published: June 25, 2024


Vulnerability identifier: #VU93288
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4727
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper input validation when processing DLAP queries. A remote non-authenticated attacker can pass a query string parameter sessionID=*, and authenticate with an existing session saved in the LDAP directory server.


Affected software

PKI
Oracle Linux
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
idm-jss
idm-jss-javadoc
idm-ldapjdk
idm-ldapjdk-javadoc
idm-tomcatjss
pki-server
pki-symkey
pki-tools
pki-base-java
pki-base
pki-ca
pki-kra
pki-javadoc
pki-core (Red Hat package)
idm-pki-base-java
idm-pki-base
idm-pki-acme
idm-pki-kra
idm-pki-server
idm-pki-tools
idm-pki-symkey
python3-idm-pki
idm-pki-ca
pki-tps
pki-help
pki-ocsp
pki-tks
python3-pki
pki-core-debuginfo
pki-core-debugsource
pki-core
Red Hat Certificate System

How to mitigate CVE-2023-4727

Install updates from vendor's website.

PKI - update to 11.5.0
idm-jss - update to 4.11.0-1
idm-jss-javadoc - update to 4.11.0-1
idm-ldapjdk - update to 4.24.0-1
idm-ldapjdk-javadoc - update to 4.24.0-1
idm-tomcatjss - update to 7.8.0-1
pki-server - update to 10.5.18-32
pki-symkey - update to 10.5.18-32
pki-tools - update to 10.5.18-32
pki-base-java - update to 10.5.18-32
pki-base - update to 10.5.18-32
pki-ca - update to 10.5.18-32
pki-kra - update to 10.5.18-32
pki-javadoc - update to 10.5.18-32
pki-core (Red Hat package) - addressed in versions 10.5.18-32.el7_9, 11.0.6-3.el9_0, 11.3.0-2.el9_2, 11.5.0-2.el9_4
idm-pki-base-java - update to 10.15.1-1
idm-pki-base - update to 10.15.1-1
idm-pki-acme - update to 10.15.1-1
idm-pki-kra - update to 10.15.1-1
idm-pki-server - update to 10.15.1-1
idm-pki-tools - update to 10.15.1-1
idm-pki-symkey - update to 10.15.1-1
python3-idm-pki - update to 10.15.1-1
idm-pki-ca - update to 10.15.1-1
pki-symkey - addressed in versions 11.0.0-6, 11.0.0-8
pki-tools - addressed in versions 11.0.0-6, 11.0.0-8
pki-tps - addressed in versions 11.0.0-6, 11.0.0-8
pki-base - addressed in versions 11.0.0-6, 11.0.0-8
pki-base-java - addressed in versions 11.0.0-6, 11.0.0-8
pki-ca - addressed in versions 11.0.0-6, 11.0.0-8
pki-help - addressed in versions 11.0.0-6, 11.0.0-8
pki-kra - addressed in versions 11.0.0-6, 11.0.0-8
pki-ocsp - addressed in versions 11.0.0-6, 11.0.0-8
pki-server - addressed in versions 11.0.0-6, 11.0.0-8
pki-tks - addressed in versions 11.0.0-6, 11.0.0-8
python3-pki - addressed in versions 11.0.0-6, 11.0.0-8
pki-core-debuginfo - addressed in versions 11.0.0-6, 11.0.0-8
pki-core-debugsource - addressed in versions 11.0.0-6, 11.0.0-8
pki-core - addressed in versions 11.0.0-6, 11.0.0-8

External References

Related Security Bulletins