CVE-2021-20179
published 2021-03-15CVE-2021-20179: A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over…
PriorityP345high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
1.19%
64.4th percentile
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dogtag-pki | < dogtag-pki 10.10.2-2 (bullseye) | dogtag-pki 10.10.2-2 (bullseye) |
| dogtagpki | dogtagpki | < 10.5.0 | 10.5.0 |
| dogtagpki | dogtagpki | >= 10.10.1 < 10.11.0 | 10.11.0 |
| dogtagpki | dogtagpki | >= 10.5.1 < 10.8.0 | 10.8.0 |
| dogtagpki | dogtagpki | >= 10.8.1 < 10.9.0 | 10.9.0 |
| dogtagpki | dogtagpki | >= 10.9.1 < 10.10.0 | 10.10.0 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | certificate_system | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q87w-gh3f-77p7: A flaw was found in pki-core
ghsa_unreviewed·2022-05-24
CVE-2021-20179 [HIGH] CWE-863 GHSA-q87w-gh3f-77p7: A flaw was found in pki-core
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
CVE-2021-20179: A flaw was found in pki-core
osv·2021-03-15·CVSS 8.1
CVE-2021-20179 [HIGH] CVE-2021-20179: A flaw was found in pki-core
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Ubuntu
Dogtag PKI vulnerability
vendor_ubuntu·2026-04-08
CVE-2021-20179 Dogtag PKI vulnerability
Title: Dogtag PKI vulnerability
Summary: Dogtag PKI could allow unintended access to network resources.
Fraser Tweedale and Geetika Kapoor discovered that Dogtag PKI could renew a
certificate without proper authentication. An attacker could possibly use
this to repeatedly renew a compromised certificate and maintain
unauthorized access to a system or resource.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pki-core: Unprivileged users can renew any certificate
vendor_redhat·2021-03-12·CVSS 8.1
CVE-2021-20179 [HIGH] CWE-863 pki-core: Unprivileged users can renew any certificate
pki-core: Unprivileged users can renew any certificate
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Statement: - Red Hat Certificate System 10.1 has been fixed via the Red Hat Enterprise Linux 8 errata RHSA-2021:0966
- Red Hat Certificate System 10.2 and newer are not
Debian
CVE-2021-20179: dogtag-pki - A flaw was found in pki-core. An attacker who has successfully compromised a key...
vendor_debian·2021·CVSS 8.1
CVE-2021-20179 [HIGH] CVE-2021-20179: dogtag-pki - A flaw was found in pki-core. An attacker who has successfully compromised a key...
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Scope: local
bullseye: resolved (fixed in 10.10.2-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1914379https://github.com/dogtagpki/pki/pull/3474https://github.com/dogtagpki/pki/pull/3475https://github.com/dogtagpki/pki/pull/3476https://github.com/dogtagpki/pki/pull/3477https://github.com/dogtagpki/pki/pull/3478https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDOLFOLEIV7I4EUC3SCZBXL6E2ER7ZEN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRE44N6P24AEDKRMWK7RPRLMCUUBRJII/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3I7BRAHLE2WWSY76W3CKFCF5WSSAE24/https://bugzilla.redhat.com/show_bug.cgi?id=1914379https://github.com/dogtagpki/pki/pull/3474https://github.com/dogtagpki/pki/pull/3475https://github.com/dogtagpki/pki/pull/3476https://github.com/dogtagpki/pki/pull/3477https://github.com/dogtagpki/pki/pull/3478https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDOLFOLEIV7I4EUC3SCZBXL6E2ER7ZEN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRE44N6P24AEDKRMWK7RPRLMCUUBRJII/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3I7BRAHLE2WWSY76W3CKFCF5WSSAE24/
2021-03-15
Published