CVE-2021-20179
An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- dogtagpki/dogtagpki · redhat/certificate system · redhat/enterprise linux · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1914379Issue Tracking, Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3474Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3475Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3476Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3477Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3478Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDOLFOLEIV7I4EUC3SCZBXL6E2ER7ZEN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRE44N6P24AEDKRMWK7RPRLMCUUBRJII/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3I7BRAHLE2WWSY76W3CKFCF5WSSAE24/
- https://bugzilla.redhat.com/show_bug.cgi?id=1914379Issue Tracking, Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3474Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3475Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3476Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3477Patch, Third Party Advisory
- https://github.com/dogtagpki/pki/pull/3478Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDOLFOLEIV7I4EUC3SCZBXL6E2ER7ZEN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRE44N6P24AEDKRMWK7RPRLMCUUBRJII/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3I7BRAHLE2WWSY76W3CKFCF5WSSAE24/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.