Since this seems related to a bad design in PKI(z) token for which the fix isn't easily backportable, I suggest a B type of bug.
Also, since this requires a fair amount of social engineering to abuse this bug, is there a good reason to keep this under embargo ?
Since this seems related to a bad design in PKI(z) token for which the fix isn't easily backportable, I suggest a B type of bug.
Also, since this requires a fair amount of social engineering to abuse this bug, is there a good reason to keep this under embargo ?