CVE-2021-27099
Last modified
CVE-2021-27099 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker controls the value of an EC2 tag prior to attestation, and the attestor is configured for agent ID templating where the tag value is the last element in the path. This issue has been fixed in SPIRE versions 0.11.3 and 0.12.1. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker controls the value of an EC2 tag prior to attestation, and the attestor is configured for agent ID templating where the tag value is the last element in the path. This issue has been fixed in SPIRE versions 0.11.3 and 0.12.1
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cncf | Spire | < 0.8.5 |
| Cncf | Spire | >= 0.9.0, < 0.9.4 |
| Cncf | Spire | >= 0.10.0, < 0.10.2 |
| Cncf | Spire | >= 0.11.0, < 0.11.3 |
| Cncf | Spire | >= 0.12.0, < 0.12.1 |
References
- https://github.com/spiffe/spire/security/advisories/GHSA-q7gm-mjrg-44h9Patch, Third Party Advisory
- https://github.com/spiffe/spire/security/advisories/GHSA-q7gm-mjrg-44h9Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-27099?
How severe is CVE-2021-27099?
How do I fix CVE-2021-27099?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-27093Windows Kernel Information Disclosure Vulnerability5.5
- CVE-2021-27094Windows Early Launch Antimalware Driver Security Feature Byp…4.4
- CVE-2021-27095Windows Media Video Decoder Remote Code Execution Vulnerabil…7.8
- CVE-2021-27096NTFS Elevation of Privilege Vulnerability7.8
- CVE-2021-27097The boot loader in Das U-Boot before 2021.04-rc2 mishandles …7.8
- CVE-2021-27098In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10…8.1
- CVE-2021-27101Accellion FTA 9_12_370 and earlier is affected by SQL inject…9.8
- CVE-2021-27102Accellion FTA 9_12_411 and earlier is affected by OS command…7.8
- CVE-2021-27103Accellion FTA 9_12_411 and earlier is affected by SSRF via a…9.8
- CVE-2021-27104Accellion FTA 9_12_370 and earlier is affected by OS command…9.8
- CVE-2021-27112LightCMS v1.3.5 contains a remote code execution vulnerabili…9.8
- CVE-2021-27113An issue was discovered in D-Link DIR-816 A2 1.10 B05 device…9.8
Are you affected by CVE-2021-27099?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
