CVE-2021-20179: High severity dogtag certificate system vulnerability
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Other sources
It was found that an unprivileged user can renew a certificate.
An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked.
References:
https://github.com/dogtagpki/pki/pull/3478 https://github.com/dogtagpki/pki/pull/3477 https://github.com/dogtagpki/pki/pull/3476 https://github.com/dogtagpki/pki/pull/3475 https://github.com/dogtagpki/pki/pull/3474
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20179.
What is the affected software?
The affected software is pki-core version 10.5 up to exclusive 10.11.
What is the severity of CVE-2021-20179?
The severity of CVE-2021-20179 is high with a CVSS score of 8.1.
How does CVE-2021-20179 affect data confidentiality and integrity?
CVE-2021-20179 can lead to data confidentiality and integrity breaches.
How can I mitigate the vulnerability?
Apply the recommended patches or updates for pki-core version 10.5 up to exclusive 10.11.