Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hxcm-7rgp-cmh6

Опубликовано: 03 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.

EPSS

Процентиль: 23%
0.00076
Низкий

8.2 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.2
nvd
больше 2 лет назад

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.

EPSS

Процентиль: 23%
0.00076
Низкий

8.2 High

CVSS3

Дефекты

CWE-287