CVE-2021-3698
Summary
| CVE | CVE-2021-3698 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:42:00 UTC |
| Updated | 2022-03-14 23:59:00 UTC |
| Description | A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1992149 – (CVE-2021-3698) CVE-2021-3698 cockpit: authenticates with revoked certificates |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159832 Oracle Enterprise Linux Security Update for cockpit (ELSA-2022-2008)
- 183767 Debian Security Update for cockpit (CVE-2021-3698)
- 240279 Red Hat Update for cockpit security (RHSA-2022:2008)
- 282239 Fedora Security Update for cockpit (FEDORA-2022-675c38e70e)
- 900771 Common Base Linux Mariner (CBL-Mariner) Security Update for cockpit (8933)
- 902037 Common Base Linux Mariner (CBL-Mariner) Security Update for cockpit (8933-1)
- 940570 AlmaLinux Security Update for cockpit (ALSA-2022:2008)
- 960127 Rocky Linux Security Update for cockpit (RLSA-2022:2008)