Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Step-ca | Smallstep | * | 0.30.0 (excluding) |
| Step-ca | Smallstep | 0.30.0-rc1 (including) | 0.30.0-rc1 (including) |
| Step-ca | Smallstep | 0.30.0-rc2 (including) | 0.30.0-rc2 (including) |
| Step-ca | Smallstep | 0.30.0-rc3 (including) | 0.30.0-rc3 (including) |
| Step-ca | Smallstep | 0.30.0-rc4 (including) | 0.30.0-rc4 (including) |
| Step-ca | Smallstep | 0.30.0-rc5 (including) | 0.30.0-rc5 (including) |
| Step-ca | Smallstep | 0.30.0-rc6 (including) | 0.30.0-rc6 (including) |