PT-2021-22799 · Primekey · Ejbca

Published

2021-08-25

·

Updated

2024-03-06

·

CVE-2021-40089

CVSS v3.1

2.3

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions PrimeKey EJBCA versions prior to 7.6.0
Description An issue was found where the General Purpose Custom Publisher could still run even when the System Configuration setting Enable External Script Access was disabled. Although this setting prevents the creation of new publishers, existing publishers would continue to run.
Recommendations For versions prior to 7.6.0, update to version 7.6.0 or later to resolve the issue. As a temporary workaround, consider disabling existing General Purpose Custom Publishers to minimize the risk of exploitation.

Fix

Related Identifiers

BIT-EJBCA-2021-40089
CVE-2021-40089

Affected Products

Ejbca