CVE-2025-3026: Improper Neutralization of Special Elements vulnerability in EJBCA
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulate the generated links and thus redirect the client to a different base URL. In this way, an attacker could insert his own server for the client to send HTTP requests, provided he succeeds in exploiting it.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3026?
CVE-2025-3026 is considered a critical vulnerability due to its potential for URL manipulation and client redirection.
How do I fix CVE-2025-3026?
To fix CVE-2025-3026, update the EJBCA service to the latest version that addresses this vulnerability.
What versions of EJBCA are affected by CVE-2025-3026?
CVE-2025-3026 specifically affects EJBCA version 8.0 Enterprise and possibly lower versions.
What types of attacks can CVE-2025-3026 enable?
CVE-2025-3026 can enable phishing attacks by redirecting users to malicious sites through manipulated HTTP headers.
Where can I find more information about CVE-2025-3026?
More information about CVE-2025-3026 can be found in security advisories and vulnerability databases.