The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
| Software | From | Fixed in |
|---|---|---|
| oracle / linux | 6 | 6.x |
| oracle / linux | 7 | 7.x |
| fedoraproject / fedora | 25 | 25.x |
| fedoraproject / fedora | 24 | 24.x |
| fedoraproject / fedora | 23 | 23.x |