BIT-ejbca-2021-40087

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ejbca/BIT-ejbca-2021-40087.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ejbca-2021-40087
Aliases
  • CVE-2021-40087
Published
2024-03-06T10:52:04.494Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.

Database specific
{
    "severity": "Low",
    "cpes": [
        "cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*"
    ]
}
References

Affected packages

Bitnami / ejbca

Package

Name
ejbca
Purl
pkg:bitnami/ejbca

Severity

  • 2.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.6.0