{"id":"CVE-2017-2590","details":"A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.","modified":"2026-07-08T05:51:33.221805700Z","published":"2018-07-27T18:29:00.627Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux","cpes":["cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"]},{"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_desktop","cpes":["cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}]},{"cpes":["cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_server"},{"extracted_events":[{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.4"},{"last_affected":"7.4"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_server_aus","cpes":["cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*"]},{"vendor_product":"redhat:enterprise_linux_server_eus","cpes":["cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.4"},{"last_affected":"7.4"},{"introduced":"7.5"},{"last_affected":"7.5"}],"source":"CPE_STRING"},{"vendor_product":"redhat:enterprise_linux_workstation","cpes":["cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0388.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96557"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2590"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freeipa/freeipa","events":[{"introduced":"0"},{"fixed":"4c1d737656f117a85845fdcd49cbe71459d392e7"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.4.0"}]}}],"versions":["alpha_1-4-4-0","release-4-2-0","alpha_1-4-2-0","release-4-0-0","release-3-3-0","beta_2-3-3-0","beta_1-3-3-0","release-3-2-0","beta_1-3-2-0","release-3-2-0-pre1","release-3-1-0","beta_2-3-0-0","beta_1-3-0-0","release-2-1-0","release-2-0-0","rc_3-2-0-0","rc_2-2-0-0","rc_1-2-0-0","beta_1-2-0-0","alpha_5-1-9-0-1","alpha_5-1-9-0","alpha_4-1-9-0","alpha_3-1-9-0","alpha_2-1-9-0","alpha-1-9-0","release-1-1-0","release-1-0-0","milestone_6","milestone_4_1","milestone_4","milestone_3","milestone_2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2590.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}