← Back

CVE-2021-3551

nvd nist
Published: Feb 16, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.

Affected (13)

Products: Dogtagpki: Dogtagpki · Fedoraproject: Fedora · Oracle: Linux · +1 more
Show all products
1 product
Dogtagpki
1 product
Fedora
1 product
Linux
9 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 10.10.0 to 10.10.6
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8
Configuration D
9 vulnerable

References (2)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory

Timeline

No history available yet.