Dogtagpki maintains a specialized public-key infrastructure and certificate-management toolkit, a narrowly scoped but prominent product in the identity and authentication supply chain. Vulnerabilities affecting the vendor recur around application-layer weaknesses including cross-site scripting, memory management flaws, cleartext storage of sensitive data, and improper access control—exposures that reflect the complexity of credential handling and trust-store management in PKI software. A moderate tendency toward public exploit availability characterizes this vendor's disclosures; defenders should prioritize patching instances that handle production certificates and are exposed to untrusted input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dogtagpki over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2414HIGH Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbi | Jul 29, 2022 | 7.5 | 74 | NO | YES |
CVE-2018-1080HIGH Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If | Jul 3, 2018 | 8.1 | 27 | NO | NO |
CVE-2021-20179HIGH A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is no | Mar 15, 2021 | 8.1 | 26 | NO | NO |
CVE-2021-3551HIGH A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to | Feb 16, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-4213HIGH A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an | Aug 24, 2022 | 7.5 | 24 | NO | NO |
CVE-2017-7537HIGH It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially | Jul 26, 2018 | 7.5 | 24 | NO | NO |
CVE-2020-15720MEDIUM In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request fun | Jul 14, 2020 | 6.8 | 23 | NO | NO |
CVE-2019-10221MEDIUM A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitizat | Mar 20, 2020 | 6.1 | 22 | NO | NO |
CVE-2019-10179MEDIUM A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a R | Mar 20, 2020 | 6.1 | 22 | NO | NO |
CVE-2019-10178MEDIUM It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. A | Mar 18, 2020 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dogtagpki.
Media articles that mention a CVE ID that affects a product developed by Dogtagpki — matched by CVE ID, not by vendor name.