UBUNTU-CVE-2018-1080
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1080
Summary:
Details: Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.
References: https://ubuntu.com/security/CVE-2018-1080, https://bugzilla.redhat.com/show_bug.cgi?id=1556657, https://pagure.io/freeipa/issue/7453, https://www.cve.org/CVERecord?id=CVE-2018-1080
Affected packages
Package
Name: dogtag-pki
Purl: pkg:deb/ubuntu/[email protected]+git20160317-1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
