GHSA-jq46-23h4-vfpjLowCVSS 3.1

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not...

Published
July 24, 2026
Last Modified
July 24, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

🔗 References (10)