Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11628

Опубликовано: 08 апр. 2020
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client. (EJBCA's internal access control restrictions are still in place, and each respective protocol must be configured to allow for enrollment.)

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*
Версия до 6.15.2.6 (исключая)
cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*
Версия от 7.0.0 (включая) до 7.3.1.2 (исключая)

EPSS

Процентиль: 36%
0.00151
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client. (EJBCA's internal access control restrictions are still in place, and each respective protocol must be configured to allow for enrollment.)

EPSS

Процентиль: 36%
0.00151
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863