CVE-2021-20179
Summary
| CVE | CVE-2021-20179 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-15 13:15:00 UTC |
| Updated | 2023-11-07 03:28:00 UTC |
| Description | A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-20179: Fix renewal profile approval process - v10.5 by cipherboy · Pull Request #3478 · dogtagpki/pki · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 33 Update: pki-core-10.10.5-5.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE-2021-20179: Fix renewal profile approval process - v10.11 by cipherboy · Pull Request #3474 · dogtagpki/pki · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 32 Update: pki-core-10.10.5-5.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2021-20179: Fix renewal profile approval process - v10.10 by cipherboy · Pull Request #3475 · dogtagpki/pki · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE-2021-20179: Fix renewal profile approval process - v10.9 by cipherboy · Pull Request #3476 · dogtagpki/pki · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 32 Update: pki-core-10.10.5-5.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE-2021-20179: Fix renewal profile approval process - v10.8 by cipherboy · Pull Request #3477 · dogtagpki/pki · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 34 Update: dogtag-pki-10.10.5-3.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: pki-core-10.10.5-5.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 1914379 – (CVE-2021-20179) CVE-2021-20179 pki-core: Unprivileged users can renew any certificate |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] Fedora 34 Update: dogtag-pki-10.10.5-3.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159122 Oracle Enterprise Linux Security Update for pki-core:10.6 (ELSA-2021-0966)
- 179649 Debian Security Update for dogtag-pki (CVE-2021-20179)
- 239176 Red Hat Update for pki-core (RHSA-2021:0851)
- 239195 Red Hat Update for pki-core (RHSA-2021:0975)
- 239196 Red Hat Update for pki-core:10.6 (RHSA-2021:0966)
- 239239 Red Hat Update for pki-core:10.6 (RHSA-2021:1263)
- 257068 CentOS Security Update for pki-core (CESA-2021:0851)
- 281480 Fedora Security Update for pki (FEDORA-2021-344dd24c84)
- 281481 Fedora Security Update for pki (FEDORA-2021-6c412a4601)
- 281505 Fedora Security Update for dogtag (FEDORA-2021-c0d6637ca5)
- 352268 Amazon Linux Security Advisory for pki-core: ALAS2-2021-1630
- 376912 Alibaba Cloud Linux Security Update for pki-core (ALINUX2-SA-2021:0014)
- 376921 Alibaba Cloud Linux Security Update for pki-core:10.6 (ALINUX3-SA-2021:0020)
- 670245 EulerOS Security Update for pki-core (EulerOS-SA-2021-1831)
- 670314 EulerOS Security Update for pki-core (EulerOS-SA-2021-1910)
- 670339 EulerOS Security Update for pki-core (EulerOS-SA-2021-1885)
- 670869 EulerOS Security Update for pki-core (EulerOS-SA-2021-1910)
- 940140 AlmaLinux Security Update for pki-core:10.6 (ALSA-2021:0966)
- 960719 Rocky Linux Security Update for pki-core:10.6 (RLSA-2021:0966)