cbcvebase.
CVE-2021-20179
published 2021-03-15

CVE-2021-20179: A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over…

PriorityP345high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
1.19%
64.4th percentile
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandogtag-pki< dogtag-pki 10.10.2-2 (bullseye)dogtag-pki 10.10.2-2 (bullseye)
dogtagpkidogtagpki< 10.5.010.5.0
dogtagpkidogtagpki>= 10.10.1 < 10.11.010.11.0
dogtagpkidogtagpki>= 10.5.1 < 10.8.010.8.0
dogtagpkidogtagpki>= 10.8.1 < 10.9.010.9.0
dogtagpkidogtagpki>= 10.9.1 < 10.10.010.10.0
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
redhatcertificate_system
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.