Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3698

Опубликовано: 10 мар. 2022
Источник: debian
EPSS Низкий

Описание

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cockpitfixed260-1package
cockpitno-dsabullseyepackage
cockpitnot-affectedbusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1992149

  • Needs sssd 2.6.1

  • https://cockpit-project.org/blog/cockpit-260.html

EPSS

Процентиль: 35%
0.00139
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
redhat
почти 4 года назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

rocky
около 3 лет назад

Moderate: cockpit security, bug fix, and enhancement update

EPSS

Процентиль: 35%
0.00139
Низкий