CVE-2016-5404 vulnerability in Freeipa and Other Products
Published on September 7, 2016
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
Products Associated with CVE-2016-5404
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2016-5404 are published in these products:
Exploit Probability
EPSS
0.66%
Percentile
70.84%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.