CVE-2021-20179

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
dogtagpkidogtagpki
𝑥
< 10.5.0
dogtagpkidogtagpki
10.5.1 ≤
𝑥
< 10.8.0
dogtagpkidogtagpki
10.8.1 ≤
𝑥
< 10.9.0
dogtagpkidogtagpki
10.9.1 ≤
𝑥
< 10.10.0
dogtagpkidogtagpki
10.10.1 ≤
𝑥
< 10.11.0
redhatcertificate_system
10.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dogtag-pki
bullseye
10.10.2-3
fixed
sid
11.2.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dogtag-pki
noble
dne
mantic
Fixed 10.10.2-2
released
lunar
Fixed 10.10.2-2
released
kinetic
Fixed 10.10.2-2
released
jammy
Fixed 10.10.2-2
released
impish
Fixed 10.10.2-2
released
hirsute
Fixed 10.10.2-2
released
groovy
ignored
focal
needed
bionic
needed
xenial
not-affected
trusty
dne