CVE Vulnerabilities

CVE-2021-29792

Improper Privilege Management

Published: Jul 12, 2021 | Modified: Jul 14, 2021
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster and gain privileges of another user. IBM X-Force ID: 203450.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Event_streams Ibm 10.0.0 (including) 10.0.0 (including)
Event_streams Ibm 10.1.0 (including) 10.1.0 (including)
Event_streams Ibm 10.2.0 (including) 10.2.0 (including)
Event_streams Ibm 10.3.0 (including) 10.3.0 (including)

Potential Mitigations

References