PT-2020-12740 · Primekey · Ejbca
Published
2020-04-07
·
Updated
2020-04-08
·
CVE-2020-11630
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EJBCA versions prior to 6.15.2.6
EJBCA versions 7.x prior to 7.3.1.2
Description
An issue was discovered in the verification of serialized objects sent between nodes connected via the Peers protocol, allowing insecure objects to be deserialized.
Recommendations
For EJBCA versions prior to 6.15.2.6, update to version 6.15.2.6 or later.
For EJBCA versions 7.x prior to 7.3.1.2, update to version 7.3.1.2 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ejbca