CVE-2023-4727EPSS p48.2%
CVE-2023-4727CVE-2023-4727
Description
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.66% probability of exploitation · percentile 48.2% · 2026-08-11T12:00:17Z |
| Last modified | 2026-06-26 |