CVE-2021-4076
published 2022-03-02CVE-2021-4076: A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.56%
72.8th percentile
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tang | < tang 11-1 (bookworm) | tang 11-1 (bookworm) |
| tang_project | tang | — | — |
| tang_project | tang | >= 0 < 8-3+deb11u1 | 8-3+deb11u1 |
| tang_project | tang | >= 0 < 11-1 | 11-1 |
| tang_project | tang | >= 0 < 11-1 | 11-1 |
| tang_project | tang | >= 0 < 11-1 | 11-1 |
| tang_project | tang | >= 8 < 11 | 11 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tang: private key leak
vendor_redhat·2021-12-07·CVSS 7.5
CVE-2021-4076 [HIGH] CWE-200 tang: private key leak
tang: private key leak
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
Package: tang (Red Hat Enterprise Linux 7) - Not affected
Package: tang (Red Hat Enterprise Linux 8) - Not affected
Package: tang (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-4076: tang - A flaw exists in tang, a network-based cryptographic binding server, which could...
vendor_debian·2021·CVSS 7.5
CVE-2021-4076 [HIGH] CVE-2021-4076: tang - A flaw exists in tang, a network-based cryptographic binding server, which could...
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
Scope: local
bookworm: resolved (fixed in 11-1)
bullseye: resolved (fixed in 8-3+deb11u1)
forky: resolved (fixed in 11-1)
sid: resolved (fixed in 11-1)
trixie: resolved (fixed in 11-1)
GHSA
GHSA-83f4-c2vq-g2p3: A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys
ghsa_unreviewed·2022-03-04
CVE-2021-4076 [HIGH] GHSA-83f4-c2vq-g2p3: A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
OSV
CVE-2021-4076: A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys
osv·2022-03-02·CVSS 7.5
CVE-2021-4076 [HIGH] CVE-2021-4076: A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2029814https://github.com/latchset/tang/commit/e82459fda10f0630c3414ed2afbc6320bb9ea7c9https://github.com/latchset/tang/pull/81https://bugzilla.redhat.com/show_bug.cgi?id=2029814https://github.com/latchset/tang/commit/e82459fda10f0630c3414ed2afbc6320bb9ea7c9https://github.com/latchset/tang/pull/81
2022-03-02
Published