CVE Vulnerabilities

CVE-2021-40089

Published: Aug 25, 2021 | Modified: Sep 09, 2021
CVSS 3.x
2.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled its not possible to create new such publishers, but existing publishers would continue to run.

Affected Software

Name Vendor Start Version End Version
Ejbca Primekey * 7.6.0 (excluding)

References