CVE-2021-20179

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
dogtagpkidogtagpki
𝑥
< 10.5.0
dogtagpkidogtagpki
10.5.1 ≤
𝑥
< 10.8.0
dogtagpkidogtagpki
10.8.1 ≤
𝑥
< 10.9.0
dogtagpkidogtagpki
10.9.1 ≤
𝑥
< 10.10.0
dogtagpkidogtagpki
10.10.1 ≤
𝑥
< 10.11.0
redhatcertificate_system
10.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dogtag-pki
bullseye
10.10.2-3
fixed
sid
11.2.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dogtag-pki
bionic
needed
focal
needed
groovy
ignored
hirsute
Fixed 10.10.2-2
released
impish
Fixed 10.10.2-2
released
jammy
Fixed 10.10.2-2
released
kinetic
Fixed 10.10.2-2
released
lunar
Fixed 10.10.2-2
released
mantic
Fixed 10.10.2-2
released
noble
dne
trusty
dne
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
pki-base
RHEL 7
0:10.5.18-12.el7_9
fixed
pki-base-java
RHEL 7
0:10.5.18-12.el7_9
fixed
pki-ca
RHEL 7
0:10.5.18-12.el7_9
fixed
pki-javadoc
RHEL 7
0:10.5.18-12.el7_9
fixed
pki-kra
RHEL 7
0:10.5.18-12.el7_9
fixed
pki-server
RHEL 7
0:10.5.18-12.el7_9
fixed
pki-symkey
RHEL 7
0:10.5.18-12.el7_9
fixed
pki-tools
RHEL 7
0:10.5.18-12.el7_9
fixed