The vendor explicitly identifies these products as affected by this CVE.
- pki-core.src as a component of Red Hat Certificate System 9
- dogtag-pki.src as a component of Red Hat Enterprise Linux 10
- idm-pki-acme as a component of Red Hat Enterprise Linux 10
- idm-pki-base as a component of Red Hat Enterprise Linux 10
- idm-pki-ca as a component of Red Hat Enterprise Linux 10
- idm-pki-java as a component of Red Hat Enterprise Linux 10
- idm-pki-kra as a component of Red Hat Enterprise Linux 10
- idm-pki-server as a component of Red Hat Enterprise Linux 10
- idm-pki-tools as a component of Red Hat Enterprise Linux 10
- python3-idm-pki as a component of Red Hat Enterprise Linux 10
- pki-ca as a component of Red Hat Enterprise Linux 6
- pki-common as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
- Remediation
- Until a fixed package is available, restrict membership in CA Administrator and equivalent roles to fully trusted operators, and audit certificate profile import operations for unexpected or unrecognized profile content. Review any custom ExternalProcessConstraint executable configuration in Dogtag for unnecessary exposure.
