HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-34196

CVSS 8.2v3.1pub. 2023-08-03upd. 2024-11-21

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
  • Keyfactor Ejbca

    APP
    Keyfactor
    < 8.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoSAuth Bypass
CWE
References

Related vulnerabilities

CVE-2024-36066LOW3.1same product

Klient CMP CLI w KeyFactor EJBCA wcześniejszy niż 8.3.1 używa tylko 6 oktetów salt, co nie jest zgodne z wymog...

CVE-2024-42006HIGH7.5same vendor

Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

CVE-2024-34458HIGH7.5same vendor

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in inf...

CVE-2025-26787MEDIUM4.7same vendor

Błąd w logice startowania kontenera SignServer znaleziono w wersjach Keyfactor SignServer wcześniejszych niż 7...

CVE-2025-47222MEDIUM6.5same vendor

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class n...