Dogtag PKI 10.10.3

CPE Details

Dogtag PKI 10.10.3
10.10.3
2021-03-16
10h48 +00:00
2021-03-17
16h50 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:dogtagpki:dogtagpki:10.10.3:*:*:*:*:*:*:*

Informations

Vendor

dogtagpki

Product

dogtagpki

Version

10.10.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-3551 2022-02-16 15h37 +00:00 A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
7.8
High
CVE-2021-20179 2021-03-15 11h01 +00:00 A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
8.1
High
CVE-2019-10178 2020-03-18 13h57 +00:00 It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
6.1
Medium