BIT-ejbca-2021-40089
Dashboard / Vulnerabilities / BIT-ejbca-2021-40089
Summary:
Details: An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to create new such publishers, but existing publishers would continue to run.
References: https://support.primekey.com/news/posts/54, https://nvd.nist.gov/vuln/detail/CVE-2021-40089
Affected packages
Package
Name: ejbca
Purl: pkg:bitnami/ejbca
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -7.6.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
