PT-2025-48988 · Step Ca · Step Ca

CVE-2025-66406

·

Publicado

2025-12-03

·

Atualizado

2026-01-30

CVSS v3.1

5.0

Média

VetorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Step CA versions prior to 0.29.0
Description Step CA is an online certificate authority for secure, automated certificate management for DevOps. A flaw exists in the authorization check for SSH certificate revocation, specifically impacting deployments configured with the SSHPOP provisioner. This issue allows for potential unauthorized actions related to SSH certificate revocation.
Recommendations Update to version 0.29.0 or later.

Exploit

Correção

Improper Authorization

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CLEANSTART-2026-KV78041
CVE-2025-66406
GHSA-J7C9-79X7-8HPR
GO-2025-4181
SUSE-SU-2025:4395-1

Produtos afetados

Step Ca