Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-30836

Опубликовано: 19 мар. 2026
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:smallstep:step-ca:*:*:*:*:*:go:*:*
Версия до 0.30.0 (исключая)
cpe:2.3:a:smallstep:step-ca:0.30.0:rc1:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc2:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc3:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc4:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc5:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc6:*:*:*:go:*:*

EPSS

Процентиль: 22%
0.00296
Низкий

10 Critical

CVSS3

Дефекты

CWE-287
CWE-295

Связанные уязвимости

CVSS3: 10
ubuntu
5 месяцев назад

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

CVSS3: 10
redhat
5 месяцев назад

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

CVSS3: 10
github
5 месяцев назад

step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)

EPSS

Процентиль: 22%
0.00296
Низкий

10 Critical

CVSS3

Дефекты

CWE-287
CWE-295