Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40089

Опубликовано: 25 авг. 2021
Источник: nvd
CVSS3: 2.3
CVSS2: 1.9
EPSS Низкий

Описание

An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to create new such publishers, but existing publishers would continue to run.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*
Версия до 7.6.0 (исключая)

EPSS

Процентиль: 17%
0.00053
Низкий

2.3 Low

CVSS3

1.9 Low

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to create new such publishers, but existing publishers would continue to run.

EPSS

Процентиль: 17%
0.00053
Низкий

2.3 Low

CVSS3

1.9 Low

CVSS2

Дефекты

NVD-CWE-noinfo