PT-2025-13686 · Ejbca · Ejbca
Published
2025-03-31
·
Updated
2025-10-10
·
CVE-2025-3027
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
EJBCA version 8.0 Enterprise
Description
The issue exists in the EJBCA service, where a small change to the PATH of the URL associated with the service causes the server to fail in finding the requested file, resulting in a redirect to an external page. This could allow users to be redirected to potentially malicious external sites, which can be exploited for phishing or other social engineering attacks.
Recommendations
For EJBCA version 8.0 Enterprise, consider restricting access to external redirects until a patch is available. As a temporary workaround, review and validate all URL paths associated with the EJBCA service to prevent unauthorized redirects.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ejbca