Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:0966

Опубликовано: 23 мар. 2021
Источник: rocky
Оценка: Important

Описание

Important: pki-core:10.6 security update

The Public Key Infrastructure (PKI) Core contains fundamental packages required by Rocky Enterprise Software Foundation Certificate System.

Security Fix(es):

  • pki-core: Unprivileged users can renew any certificate (CVE-2021-20179)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
ldapjdknoarch1.module+el8.4.0+418+b7ae1d4aldapjdk-4.22.0-1.module+el8.4.0+418+b7ae1d4a.noarch.rpm
ldapjdknoarch1.module+el8.4.0+418+b7ae1d4aldapjdk-4.22.0-1.module+el8.4.0+418+b7ae1d4a.noarch.rpm
ldapjdk-javadocnoarch1.module+el8.4.0+418+b7ae1d4aldapjdk-javadoc-4.22.0-1.module+el8.4.0+418+b7ae1d4a.noarch.rpm
ldapjdk-javadocnoarch1.module+el8.4.0+418+b7ae1d4aldapjdk-javadoc-4.22.0-1.module+el8.4.0+418+b7ae1d4a.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 5 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 8.1
redhat
почти 5 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 8.1
nvd
почти 5 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 8.1
debian
почти 5 лет назад

A flaw was found in pki-core. An attacker who has successfully comprom ...

CVSS3: 8.1
github
больше 3 лет назад

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.