CVE-2020-11628: Medium severity ejbca vulnerability
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client. (EJBCA's internal access control restrictions are still in place, and each respective protocol must be configured to allow for enrollment.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11628?
The severity of CVE-2020-11628 is classified as medium.
How do I fix CVE-2020-11628?
To fix CVE-2020-11628, upgrade EJBCA to version 6.15.2.6 or later, or to version 7.3.1.2 or later.
What software is affected by CVE-2020-11628?
Affected software versions of EJBCA are those prior to 6.15.2.6 and between 7.0.0 and 7.3.1.1.
What is the nature of the vulnerability in CVE-2020-11628?
CVE-2020-11628 is a protocol access control bypass vulnerability that allows unauthorized modifications of the URI string from the client.
Who is the vendor associated with CVE-2020-11628?
The vendor associated with CVE-2020-11628 is PrimeKey.