CVE-2020-11627: CSRF
Published Apr 7, 2020
·Updated
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
Affected Software
2 affected components
PrimeKey EJBCA<6.15.2.6
PrimeKey EJBCA>=7.0.0<7.3.1.2
Event History
Apr 7, 2020
CVE Published
via MITRE·11:34 PM
Data Sourced
via MITRE·11:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11627?
CVE-2020-11627 is classified as a medium severity vulnerability due to its CSRF nature affecting EJBCA.
2
What are the affected versions in CVE-2020-11627?
CVE-2020-11627 affects EJBCA versions prior to 6.15.2.6 and from 7.0.0 up to but not including 7.3.1.2.
3
How do I fix CVE-2020-11627?
To fix CVE-2020-11627, upgrade EJBCA to version 6.15.2.6 or version 7.3.1.2 or later.
4
What type of vulnerability is CVE-2020-11627?
CVE-2020-11627 is a Cross Site Request Forgery (CSRF) vulnerability found in the CA UI.
5
Can CVE-2020-11627 lead to unauthorized access?
Yes, CVE-2020-11627 could potentially allow attackers to perform actions on behalf of authenticated users without their consent.