IBM Support

Security Bulletin: Event Streams documentation for generating .p12 files incorrectly adds the CA key into the file (CVE-2021-29792)

Security Bulletin


Summary

Event Streams documentation for generating .p12 files incorrectly adds the CA private key into the file which results in the CA private key being added to the trust store. This trust store is distributed to client applications via the Event Streams UI and CLI and so gives client access to the CA private key. This issue only arises when using custom provided certificates and following the Event Streams documentation to generate the .p12 file.

Vulnerability Details

CVEID:   CVE-2021-29792
DESCRIPTION:   IBM Event Streams could allowa user the CA private key to create their own certificates and deploy them in the cluster and gain privileges of another user.
CVSS Base score: 4.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/203450 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s)Version(s)
IBM Event Streams10.0.x
IBM Event Streams10.1.x
IBM Event Streams10.2.x
IBM Event Streams10.3.x

Remediation/Fixes

When generating your PKCS12 truststore, ensure that the truststore does not contain the CA private key. This is important because the .p12 file will be available to download from the Event Streams UI and distributed to clients.

Workarounds and Mitigations

Refer to the IBM Event Streams documentation when providing a CA certificate and key.

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

11 Jun 2021: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSFHBB","label":"IBM Event Streams"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF051","label":"Linux on IBM Z Systems"}],"Version":"10.x","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
30 July 2021

UID

ibm16469451