PT-2025-13685 · Ejbca · Ejbca
Published
2025-03-31
·
Updated
2025-10-10
·
CVE-2025-3026
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
EJBCA version 8.0 Enterprise
Description
The issue exists in the EJBCA service, where modifying the
Host header in an HTTP request allows manipulation of generated links, potentially redirecting the client to a different base URL. This could enable an attacker to insert their own server, receiving HTTP requests from the client, if the issue is successfully exploited.Recommendations
For version 8.0 Enterprise, consider restricting modifications to the
Host header in HTTP requests as a temporary mitigation measure until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ejbca