Logo
vulnerabilityCVE-2021-3698
Name
CVE-2021-3698
Source
NVD ( link)Debian ( link)
Description
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
cockpit
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
352
Not Affected
yocto
scarthgap
304
Not Affected