CVE-2021-3551
published 2022-02-16CVE-2021-3551: A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.4th percentile
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dogtag-pki | — | — |
| dogtagpki | dogtagpki | >= 10.10.0 < 10.10.6 | 10.10.6 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9ggg-37fj-xc96: A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file
ghsa_unreviewed·2022-02-17
CVE-2021-3551 [HIGH] CWE-312 GHSA-9ggg-37fj-xc96: A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
OSV
CVE-2021-3551: A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file
osv·2022-02-16·CVSS 7.8
CVE-2021-3551 [HIGH] CVE-2021-3551: A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
Red Hat
pki-server: Dogtag installer "pkispawn" logs admin credentials into a world-readable log file
vendor_redhat·2021-06-03·CVSS 7.8
CVE-2021-3551 [HIGH] CWE-312 pki-server: Dogtag installer "pkispawn" logs admin credentials into a world-readable log file
pki-server: Dogtag installer "pkispawn" logs admin credentials into a world-readable log file
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
Statement:
Debian
CVE-2021-3551: dogtag-pki - A flaw was found in the PKI-server, where the spkispawn command, when run in deb...
vendor_debian·2021·CVSS 7.8
CVE-2021-3551 [HIGH] CVE-2021-3551: dogtag-pki - A flaw was found in the PKI-server, where the spkispawn command, when run in deb...
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
Scope: local
bullseye: open
No detection rules found.
No public exploits indexed.
2022-02-16
Published