CVE-2021-3698 is a flaw in Cockpit versions prior to 260, affecting products like cockpit_project cockpit and Red Hat Enterprise Linux. It allows client certificates to bypass Certificate Revocation List (CRL) checks during authentication via SSSD. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity, primarily impacting confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 260CPE matchmatch criteria | cpe:2.3:a:cockpit-project:cockpit:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
Mar 8, 2022cockpit: authenticates with revoked certificates
Aug 27, 2021