CVE-2016-5404

medium
Published 2016-09-07 · Modified 2026-05-06
CVSS v3
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2
4.0
VIR risk
6.5

Description

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-5404

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=cf74584d0f772f3f5eccc1d30c001e4212a104fd

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.3.2-5
debian debiansidfixed4.3.2-5
debian debiantrixiefixed4.3.2-5
fedora fedora23affected
fedora fedora24affected
fedora fedora25affected

Application impact

VendorProductVersionsFixed
freeipafreeipa-

References

CWEs

CWE-284

Verify integrity in audit chain (admin only). AS-IS.