CVE-2023-4727: Red Hat Certificate System 10.4 Eus For Rhel-8

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

Affected products

  • Red Hat Red Hat Certificate System 10.4 Eus For Rhel-8: before 8060020240529205458.07fb4edf (fixed in 8060020240529205458.07fb4edf)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7: before 0:10.5.18-32.el7_9 (fixed in 0:10.5.18-32.el7_9)
  • Red Hat Red Hat Enterprise Linux 8: before 8100020240614102443.82f485b7 (fixed in 8100020240614102443.82f485b7)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 8040020240329193548.17df0a3f (fixed in 8040020240329193548.17df0a3f)
  • Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service: before 8040020240329193548.17df0a3f (fixed in 8040020240329193548.17df0a3f)
  • Red Hat Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions: before 8040020240329193548.17df0a3f (fixed in 8040020240329193548.17df0a3f)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 8060020240329182634.60523a7b (fixed in 8060020240329182634.60523a7b)
  • Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 8060020240329182634.60523a7b (fixed in 8060020240329182634.60523a7b)
  • Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 8060020240329182634.60523a7b (fixed in 8060020240329182634.60523a7b)
  • Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 8080020240329143735.693a3987 (fixed in 8080020240329143735.693a3987)
  • Red Hat Red Hat Enterprise Linux 9: before 0:11.5.0-2.el9_4 (fixed in 0:11.5.0-2.el9_4)
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:11.0.6-3.el9_0 (fixed in 0:11.0.6-3.el9_0)
  • Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:11.3.0-2.el9_2 (fixed in 0:11.3.0-2.el9_2)

Published 2024-06-11. Last modified 2026-06-26.