CVE-2020-11630: Critical severity ejbca vulnerability
Published Apr 7, 2020
·Updated
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized.
Affected Software
2 affected components
PrimeKey EJBCA<6.15.2.6
PrimeKey EJBCA>=7.0.0<7.3.1.2
Event History
Apr 7, 2020
CVE Published
via MITRE·11:34 PM
Data Sourced
via MITRE·11:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11630?
CVE-2020-11630 has been classified with a high severity due to the risk of remote code execution from insecure deserialization.
2
How do I fix CVE-2020-11630?
To fix CVE-2020-11630, upgrade to EJBCA version 6.15.2.6 or 7.3.1.2 or later.
3
What are the affected versions in CVE-2020-11630?
CVE-2020-11630 affects EJBCA versions prior to 6.15.2.6 and versions in the 7.x series before 7.3.1.2.
4
What type of vulnerability is CVE-2020-11630?
CVE-2020-11630 is a deserialization vulnerability that allows insecure objects to be processed.
5
What issues can arise from CVE-2020-11630?
Exploitation of CVE-2020-11630 can lead to unauthorized remote code execution and potential system compromise.