PT-2025-13686 · Ejbca · Ejbca

Published

2025-03-31

·

Updated

2025-10-10

·

CVE-2025-3027

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EJBCA version 8.0 Enterprise
Description The issue exists in the EJBCA service, where a small change to the PATH of the URL associated with the service causes the server to fail in finding the requested file, resulting in a redirect to an external page. This could allow users to be redirected to potentially malicious external sites, which can be exploited for phishing or other social engineering attacks.
Recommendations For EJBCA version 8.0 Enterprise, consider restricting access to external redirects until a patch is available. As a temporary workaround, review and validate all URL paths associated with the EJBCA service to prevent unauthorized redirects.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-EJBCA-2025-3027
CVE-2025-3027

Affected Products

Ejbca