CVE-2021-20179

EUVD-2021-7635
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
dogtagpkidogtagpki
𝑥
< 10.5.0
dogtagpkidogtagpki
10.5.1 ≤
𝑥
< 10.8.0
dogtagpkidogtagpki
10.8.1 ≤
𝑥
< 10.9.0
dogtagpkidogtagpki
10.9.1 ≤
𝑥
< 10.10.0
dogtagpkidogtagpki
10.10.1 ≤
𝑥
< 10.11.0
redhatcertificate_system
10.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dogtag-pki
bullseye
10.10.2-3
fixed
sid
11.2.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dogtag-pki
bionic
needed
focal
needed
groovy
ignored
hirsute
Fixed 10.10.2-2
released
impish
Fixed 10.10.2-2
released
jammy
Fixed 10.10.2-2
released
kinetic
Fixed 10.10.2-2
released
lunar
Fixed 10.10.2-2
released
mantic
Fixed 10.10.2-2
released
noble
dne
trusty
dne
xenial
not-affected