CVE-2016-5404: Fedoraproject Fedora

Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

Affected products

  • Fedoraproject Fedora: version 23 only; version 24 only; version 25 only
  • Freeipa Freeipa: affected versions not specified
  • Oracle Linux: version 6 only; version 7 only

Published 2016-09-07. Last modified 2026-06-17.