CVE-2021-20179

Description

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.291

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2021:0851) pki-core security and bug fix update pki-base-10.5.18-12.el7_9.noarch.rpmLinux
(RHSA-2021:0851) pki-core security and bug fix update pki-base-java-10.5.18-12.el7_9.noarch.rpmLinux
(RHSA-2021:0851) pki-core security and bug fix update pki-ca-10.5.18-12.el7_9.noarch.rpmLinux
(RHSA-2021:0851) pki-core security and bug fix update pki-javadoc-10.5.18-12.el7_9.noarch.rpmLinux
(RHSA-2021:0851) pki-core security and bug fix update pki-kra-10.5.18-12.el7_9.noarch.rpmLinux
(RHSA-2021:0851) pki-core security and bug fix update pki-server-10.5.18-12.el7_9.noarch.rpmLinux
(RHSA-2021:0851) pki-core security and bug fix update pki-symkey-10.5.18-12.el7_9.x86_64.rpmLinux
(RHSA-2021:0851) pki-core security and bug fix update pki-tools-10.5.18-12.el7_9.x86_64.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-base-10.9.4-3.module+el8.3.0+10353+73f6df5b.noarch.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-base-java-10.9.4-3.module+el8.3.0+10353+73f6df5b.noarch.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-ca-10.9.4-3.module+el8.3.0+10353+73f6df5b.noarch.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-core-debugsource-10.9.4-3.module+el8.3.0+10353+73f6df5b.x86_64.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-kra-10.9.4-3.module+el8.3.0+10353+73f6df5b.noarch.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-server-10.9.4-3.module+el8.3.0+10353+73f6df5b.noarch.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-symkey-10.9.4-3.module+el8.3.0+10353+73f6df5b.x86_64.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update pki-tools-10.9.4-3.module+el8.3.0+10353+73f6df5b.x86_64.rpmLinux
(RHSA-2021:0966) pki-core:10.6 security update python3-pki-10.9.4-3.module+el8.3.0+10353+73f6df5b.noarch.rpmLinux
Jss update (ELSA-2021-0966) jss-4.7.3-1.module+el8.3.0+7857+983338ee.x86_64.rpmLinux
Jss-javadoc update (ELSA-2021-0966) jss-javadoc-4.7.3-1.module+el8.3.0+7857+983338ee.x86_64.rpmLinux
Ldapjdk update (ELSA-2021-0966) ldapjdk-4.22.0-1.module+el8.3.0+7857+983338ee.noarch.rpmLinux
Ldapjdk-javadoc update (ELSA-2021-0966) ldapjdk-javadoc-4.22.0-1.module+el8.3.0+7857+983338ee.noarch.rpmLinux
Pki-base update (ELSA-2021-0966) pki-base-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.noarch.rpmLinux
Pki-base-java update (ELSA-2021-0966) pki-base-java-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.noarch.rpmLinux
Pki-ca update (ELSA-2021-0966) pki-ca-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.noarch.rpmLinux
Pki-kra update (ELSA-2021-0966) pki-kra-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.noarch.rpmLinux
Pki-server update (ELSA-2021-0966) pki-server-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.noarch.rpmLinux
Pki-symkey update (ELSA-2021-0966) pki-symkey-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.x86_64.rpmLinux
Pki-tools update (ELSA-2021-0966) pki-tools-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.x86_64.rpmLinux
Python3-pki update (ELSA-2021-0966) python3-pki-10.9.4-3.0.1.module+el8.3.0+el8+9692+a35cea4e.noarch.rpmLinux
Tomcatjss update (ELSA-2021-0966) tomcatjss-7.5.0-1.module+el8.3.0+7857+983338ee.noarch.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-base-10.5.18-12.el7_9.noarch.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-base-java-10.5.18-12.el7_9.noarch.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-ca-10.5.18-12.el7_9.noarch.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-javadoc-10.5.18-12.el7_9.noarch.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-kra-10.5.18-12.el7_9.noarch.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-server-10.5.18-12.el7_9.noarch.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-symkey-10.5.18-12.el7_9.x86_64.rpmLinux
(CESA-2021:0851) pki-core security and bug fix update pki-tools-10.5.18-12.el7_9.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234