The transit path validation code in Heimdal before 7.3...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Aug 28, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.
References