Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40088

Опубликовано: 25 авг. 2021
Источник: nvd
CVSS3: 5.4
CVSS2: 4.9
EPSS Низкий

Описание

An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*
Версия до 7.6.0 (исключая)

EPSS

Процентиль: 32%
0.00127
Низкий

5.4 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.

EPSS

Процентиль: 32%
0.00127
Низкий

5.4 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-862