PatchSiren cyber security CVE debrief
CVE-2021-3560 Red Hat CVE debrief
CVE-2021-3560 is a Red Hat Polkit incorrect authorization vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, organizations should treat remediation as urgent and follow vendor update guidance as soon as possible.
- Vendor
- Red Hat
- Product
- Polkit
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2023-05-12
- Original CVE updated
- 2023-05-12
- Advisory published
- 2023-05-12
- Advisory updated
- 2023-05-12
Who should care
Red Hat administrators, Linux platform owners, endpoint and server patching teams, vulnerability management teams, and security operations teams responsible for systems that use Polkit.
Technical summary
The supplied corpus identifies the issue only as a Polkit incorrect authorization vulnerability affecting Red Hat. CISA has added it to the Known Exploited Vulnerabilities catalog, which indicates confirmed exploitation risk and makes timely patching the main defensive priority.
Defensive priority
High. CISA KEV inclusion means this issue should be prioritized ahead of non-exploited vulnerabilities, with remediation tracked against the KEV due date of 2023-06-02 in the supplied timeline.
Recommended defensive actions
- Apply updates per vendor instructions as soon as possible.
- Inventory systems that use Red Hat Polkit so affected assets can be prioritized.
- Validate remediation status across servers, endpoints, and any golden images or templates that include the product.
- If immediate patching is not possible, use compensating controls and track the exception until updates are deployed.
- Confirm completion before the CISA KEV due date shown in the supplied timeline.
Evidence notes
This debrief is limited to the supplied corpus and official links. The strongest evidence is the CISA KEV entry, which names the vulnerability as 'Red Hat Polkit Incorrect Authorization Vulnerability' and instructs organizations to apply updates per vendor instructions. The supplied source item also references the official CVE record and NVD detail page.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-3560 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-3560
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-3560 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3560
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.