-
Notifications
You must be signed in to change notification settings - Fork 152
Closed
Labels
invalidThis doesn't seem rightThis doesn't seem right
Description
While working on perforator project, I identified a vulnerability (CVE-2025-66406) in Step CA’s SSHPOP provisioner. Due to an improper authorization check, an attacker with limited access could revoke SSH certificates without proper permissions, potentially disrupting secure access across systems using these certificates.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
invalidThis doesn't seem rightThis doesn't seem right