5.7
CVSSv3

CVE-2022-2393

Published: 14/07/2022 Updated: 30/06/2023
CVSS v3 Base Score: 5.7 | Impact Score: 3.6 | Exploitability Score: 2.1
VMScore: 0

Vulnerability Summary

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pki-core project pki-core

redhat enterprise linux 7.0

redhat enterprise linux 6.0

redhat enterprise linux 8.0

redhat certificate system 9.0

redhat certificate system 10.0

redhat enterprise linux 9.0

Vendor Advisories

Debian Bug report logs - #1034802 dogtag-pki: CVE-2022-2393 Package: src:dogtag-pki; Maintainer for src:dogtag-pki is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 24 Apr 2023 20:57:02 UTC Severity: important Tags: security, upstream ...
Synopsis Moderate: pki-core security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for jss, ldapjdk, pki-core, and tomcatjss is now available for Red Hat Enterprise Linux 9Red ...
Synopsis Moderate: Red Hat Certificate System 97 CVE bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated CVE security packages are now available for Red Hat Certificate System 97Red Hat Product Securi ...
Synopsis Important: pki-core:106 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the pki-core:106 module is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat Pr ...
Synopsis Moderate: pki-core security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for pki-core is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a ...
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content (CVE-2022-2393) ...