BIT-ejbca-2021-40088

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ejbca/BIT-ejbca-2021-40088.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ejbca-2021-40088
Aliases
  • CVE-2021-40088
Published
2024-03-06T10:51:53.209Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.

Database specific
{
    "cpes": [
        "cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / ejbca

Package

Name
ejbca
Purl
pkg:bitnami/ejbca

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.6.0