MEDIUM✓ PATCH🇬🇧 English

CVE-2025-26787

CVSS 4.7v3.1pub. 2025-12-22upd. 2026-01-05

Błąd w logice startowania kontenera SignServer znaleziono w wersjach Keyfactor SignServer wcześniejszych niż 7.2. Polecenie Admin CLI używane do konfiguracji dostępu do certyfikatów podczas początkowego startu kontenera ustawia właściwość "allowany", umożliwiającą połączenie każdemu użytkownikowi z ważnym i zaufanym certyfikatem auth klienta. Administratorzy mogą następnie skonfigurować bardziej restrykcyjny dostęp do konkretnych certyfikatów. Błąd logiki spowodował, że to polecenie CLI uruchamiało się przy każdym restarcie kontenera zamiast tylko przy pierwszym starcie, resetując konfigurację do "allowany".

Pokaż oryginał (EN)

An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted client auth certificate to connect. Admins can then set more restricted access to specific certificates. A logic error caused this admin CLI command to be run on each restart of the container instead of only the first startup as intended resetting the configuration to "allowany".

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
  • Keyfactor Signserver

    APP
    Keyfactor
    < 7.2
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Container
CWE
Referencje

Powiązane podatności

CVE-2025-47220MEDIUM5.3ten sam produkt

A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNA...

CVE-2025-47221MEDIUM5.3ten sam produkt

An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODIS...

CVE-2025-47222MEDIUM6.5ten sam produkt

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class n...

CVE-2024-34458HIGH7.5ten sam vendor

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in inf...

CVE-2024-42006HIGH7.5ten sam vendor

Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.