Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3698

Опубликовано: 27 авг. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

A flaw was found in Cockpit in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

Отчет

OpenShift Container Platform (OCP) 3 has transitioned to the maintenance phase of the product life cycle and receives only qualified Critical and Important impact security fixes. This issue has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat OpenShift Container Platform 3 Life Cycle Policy - https://access.redhat.com/support/policy/updates/openshift_noncurrent

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7cockpitOut of support scope
Red Hat Enterprise Linux 9cockpitNot affected
Red Hat OpenShift Container Platform 3.11cockpitOut of support scope
Red Hat Virtualization 4cockpitNot affected
Red Hat Enterprise Linux 8cockpitFixedRHSA-2022:200810.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1992149cockpit: authenticates with revoked certificates

EPSS

Процентиль: 35%
0.00139
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it han ...

rocky
около 3 лет назад

Moderate: cockpit security, bug fix, and enhancement update

EPSS

Процентиль: 35%
0.00139
Низкий

7.5 High

CVSS3