Błąd w logice startowania kontenera SignServer znaleziono w wersjach Keyfactor SignServer wcześniejszych niż 7.2. Polecenie Admin CLI używane do konfiguracji dostępu do certyfikatów podczas początkowego startu kontenera ustawia właściwość "allowany", umożliwiającą połączenie każdemu użytkownikowi z ważnym i zaufanym certyfikatem auth klienta. Administratorzy mogą następnie skonfigurować bardziej restrykcyjny dostęp do konkretnych certyfikatów. Błąd logiki spowodował, że to polecenie CLI uruchamiało się przy każdym restarcie kontenera zamiast tylko przy pierwszym starcie, resetując konfigurację do "allowany".
▸ Pokaż oryginał (EN)
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted client auth certificate to connect. Admins can then set more restricted access to specific certificates. A logic error caused this admin CLI command to be run on each restart of the container instead of only the first startup as intended resetting the configuration to "allowany".
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LKeyfactor Signserver
APPKeyfactor< 7.2
Powiązane podatności
A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNA...
An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODIS...
A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class n...
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in inf...
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.