Search CVE reports


Toggle filters

1 – 10 of 20 results


CVE-2026-18369

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address....

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18047

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-17039

Medium priority
Needs evaluation

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-4727

Medium priority
Needs evaluation

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-2414

Medium priority

Some fixes available 1 of 4

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Fixed Ignored Ignored
Show less packages

CVE-2022-2393

Medium priority
Needs evaluation

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-3551

Low priority
Needs evaluation

A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-25715

Medium priority

Some fixes available 1 of 8

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-1721

Low priority
Vulnerable

A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Vulnerable Needs evaluation
Show less packages

CVE-2021-20179

High priority

Some fixes available 8 of 9

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Fixed Fixed Fixed
Show less packages