Vulnerabilities (CVE)

Filtered by vendor Primekey Subscribe
Filtered by product Ejbca
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40086 1 Primekey 1 Ejbca 2022-07-12 3.5 LOW 2.2 LOW
An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from direct view, checking the page source would reveal the secret.
CVE-2021-40089 1 Primekey 1 Ejbca 2021-09-09 1.9 LOW 2.3 LOW
An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to create new such publishers, but existing publishers would continue to run.
CVE-2021-40087 1 Primekey 1 Ejbca 2021-09-07 4.0 MEDIUM 2.7 LOW
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.