CVE-2021-20179

Related Vulnerabilities: CVE-2021-20179  

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

Description

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

Additional Information

  • Bugzilla 1914379: CVE-2021-20179 pki-core: Unprivileged users can renew any certificate
  • CWE-863: Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2021-20179