CVE-2016-5404: Fedoraproject Fedora
Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
Affected products
- Fedoraproject Fedora: version 23 only; version 24 only; version 25 only
- Freeipa Freeipa: affected versions not specified
- Oracle Linux: version 6 only; version 7 only
Published 2016-09-07. Last modified 2026-06-17.