CVE-2021-40086: Infoleak
An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from direct view, checking the page source would reveal the secret.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PrimeKey EJBCAto a version that resolves this vulnerability.Fixed in 7.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40086?
CVE-2021-40086 has a medium severity level due to exposure of sensitive data in configuration.
How do I fix CVE-2021-40086?
To fix CVE-2021-40086, upgrade PrimeKey EJBCA to version 7.6.0 or later.
What does CVE-2021-40086 affect?
CVE-2021-40086 affects PrimeKey EJBCA versions before 7.6.0.
Who can view the sensitive information exposed by CVE-2021-40086?
Only administrators can view the sensitive information exposed by CVE-2021-40086.
What kind of information is revealed in CVE-2021-40086?
CVE-2021-40086 reveals the enrollment secret for SCEP, CMP, EST, and Auto-enrollment.