CVE-2021-20179
pki-core: Unprivileged users can renew any certificate
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Se encontró un fallo en pki-core. Un atacante que haya comprometido con éxito una clave podría usar este fallo para renovar el certificado correspondiente una y otra vez, siempre que no se revoque explícitamente. La mayor amenaza de esta vulnerabilidad es la confidencialidad e integridad de los datos
The Public Key Infrastructure Core contains fundamental packages required by Red Hat Certificate System. Issues addressed include a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-17 CVE Reserved
- 2021-03-15 CVE Published
- 2024-08-03 CVE Updated
- 2025-05-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (10)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1914379 | 2021-04-20 | |
https://github.com/dogtagpki/pki/pull/3474 | 2023-11-07 | |
https://github.com/dogtagpki/pki/pull/3475 | 2023-11-07 | |
https://github.com/dogtagpki/pki/pull/3476 | 2023-11-07 | |
https://github.com/dogtagpki/pki/pull/3477 | 2023-11-07 | |
https://github.com/dogtagpki/pki/pull/3478 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dogtagpki Search vendor "Dogtagpki" | Dogtagpki Search vendor "Dogtagpki" for product "Dogtagpki" | < 10.5.0 Search vendor "Dogtagpki" for product "Dogtagpki" and version " < 10.5.0" | - |
Affected
| ||||||
Dogtagpki Search vendor "Dogtagpki" | Dogtagpki Search vendor "Dogtagpki" for product "Dogtagpki" | >= 10.5.1 < 10.8.0 Search vendor "Dogtagpki" for product "Dogtagpki" and version " >= 10.5.1 < 10.8.0" | - |
Affected
| ||||||
Dogtagpki Search vendor "Dogtagpki" | Dogtagpki Search vendor "Dogtagpki" for product "Dogtagpki" | >= 10.8.1 < 10.9.0 Search vendor "Dogtagpki" for product "Dogtagpki" and version " >= 10.8.1 < 10.9.0" | - |
Affected
| ||||||
Dogtagpki Search vendor "Dogtagpki" | Dogtagpki Search vendor "Dogtagpki" for product "Dogtagpki" | >= 10.9.1 < 10.10.0 Search vendor "Dogtagpki" for product "Dogtagpki" and version " >= 10.9.1 < 10.10.0" | - |
Affected
| ||||||
Dogtagpki Search vendor "Dogtagpki" | Dogtagpki Search vendor "Dogtagpki" for product "Dogtagpki" | >= 10.10.1 < 10.11.0 Search vendor "Dogtagpki" for product "Dogtagpki" and version " >= 10.10.1 < 10.11.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Certificate System Search vendor "Redhat" for product "Certificate System" | 10.0 Search vendor "Redhat" for product "Certificate System" and version "10.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 8.0 Search vendor "Redhat" for product "Enterprise Linux" and version "8.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 32 Search vendor "Fedoraproject" for product "Fedora" and version "32" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
|