Vulnerabilities > CVE-2021-20179 - Incorrect Authorization vulnerability in multiple products

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE

Summary

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

Vulnerable Configurations

Part Description Count
Application
Dogtagpki
79
Application
Redhat
1
OS
Redhat
2
OS
Fedoraproject
3

Common Weakness Enumeration (CWE)