NA

CVE-2021-40089

Published: 25/08/2021 Updated: 09/09/2021
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 2.3 | Impact Score: 1.4 | Exploitability Score: 0.8
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in PrimeKey EJBCA prior to 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to create new such publishers, but existing publishers would continue to run.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

primekey ejbca