First published: Fri Jan 08 2021(Updated: )
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dogtagpki Dogtagpki | <10.5.0 | |
Dogtagpki Dogtagpki | >=10.5.1<10.8.0 | |
Dogtagpki Dogtagpki | >=10.8.1<10.9.0 | |
Dogtagpki Dogtagpki | >=10.9.1<10.10.0 | |
Dogtagpki Dogtagpki | >=10.10.1<10.11.0 | |
Redhat Certificate System | =10.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
redhat/pki-core | <10.5 | 10.5 |
redhat/pki-core | <10.8 | 10.8 |
redhat/pki-core | <10.10 | 10.10 |
redhat/pki-core | <10.11 | 10.11 |
redhat/pki-core | <0:10.5.18-12.el7_9 | 0:10.5.18-12.el7_9 |
redhat/pki-core | <0:10.5.9-15.el7_6 | 0:10.5.9-15.el7_6 |
redhat/pki-core | <0:10.5.16-7.el7_7 | 0:10.5.16-7.el7_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2021-20179.
The affected software is pki-core version 10.5 up to exclusive 10.11.
The severity of CVE-2021-20179 is high with a CVSS score of 8.1.
CVE-2021-20179 can lead to data confidentiality and integrity breaches.
Apply the recommended patches or updates for pki-core version 10.5 up to exclusive 10.11.