CVE-2021-27098
Last modified
CVE-2021-27098 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible issuance of an X.509 certificate with a URI SAN for a SPIFFE ID that the agent is not authorized to distribute. Proper controls are in place to require that the caller presents a valid agent certificate that is already authorized to issue at least one SPIFFE ID, and the requested SPIFFE ID belongs to the same trust domain, prior to being able to trigger this vulnerability. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible issuance of an X.509 certificate with a URI SAN for a SPIFFE ID that the agent is not authorized to distribute. Proper controls are in place to require that the caller presents a valid agent certificate that is already authorized to issue at least one SPIFFE ID, and the requested SPIFFE ID belongs to the same trust domain, prior to being able to trigger this vulnerability. This issue has been fixed in SPIRE versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cncf | Spire | >= 0.8.1, <= 0.8.4 |
| Cncf | Spire | >= 0.9.0, < 0.9.4 |
| Cncf | Spire | >= 0.10.0, < 0.10.2 |
| Cncf | Spire | >= 0.11.0, < 0.11.3 |
| Cncf | Spire | >= 0.12.0, < 0.12.1 |
References
- https://github.com/spiffe/spire/security/advisories/GHSA-h746-rm5q-8mgqThird Party Advisory
- https://github.com/spiffe/spire/security/advisories/GHSA-h746-rm5q-8mgqThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-27098?
How severe is CVE-2021-27098?
How do I fix CVE-2021-27098?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-27092Azure AD Web Sign-in Security Feature Bypass Vulnerability6.8
- CVE-2021-27093Windows Kernel Information Disclosure Vulnerability5.5
- CVE-2021-27094Windows Early Launch Antimalware Driver Security Feature Byp…4.4
- CVE-2021-27095Windows Media Video Decoder Remote Code Execution Vulnerabil…7.8
- CVE-2021-27096NTFS Elevation of Privilege Vulnerability7.8
- CVE-2021-27097The boot loader in Das U-Boot before 2021.04-rc2 mishandles …7.8
- CVE-2021-27099In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.…6.8
- CVE-2021-27101Accellion FTA 9_12_370 and earlier is affected by SQL inject…9.8
- CVE-2021-27102Accellion FTA 9_12_411 and earlier is affected by OS command…7.8
- CVE-2021-27103Accellion FTA 9_12_411 and earlier is affected by SSRF via a…9.8
- CVE-2021-27104Accellion FTA 9_12_370 and earlier is affected by OS command…9.8
- CVE-2021-27112LightCMS v1.3.5 contains a remote code execution vulnerabili…9.8
Are you affected by CVE-2021-27098?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
