OESA-2023-1419
Dashboard / Vulnerabilities / OESA-2023-1419
Summary: pki-core security update
Details: Dogtag PKI is a designed enterprise software system manage enterprise Public Key Infrastructure deployments. Security Fix(es): Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.(CVE-2022-2414)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1419, https://nvd.nist.gov/vuln/detail/CVE-2022-2414
Affected packages
Package
Name: pki-core
Purl: pkg:rpm/openEuler/pki-core&distro=openEuler-22.03-LTS-SP2
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -11.0.0-5.oe2203sp2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
