Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-36066
Disclosure Date: September 12, 2024 (last updated September 19, 2024)
The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle attacks easier. CMP includes password-based MAC as one of the options for message integrity and authentication (the other option is certificate-based). RFC 4211 section 4.4 requires that password-based MAC parameters use a salt with a random value of at least 8 octets. This helps to inhibit dictionary attacks. Because the standalone CMP client originally was developed as test code, the salt was instead hardcoded and only 6 octets long.
0
Attacker Value
Unknown
CVE-2024-42006
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
0
Attacker Value
Unknown
CVE-2024-34458
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.
0
Attacker Value
Unknown
CVE-2023-34196
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.
0
Attacker Value
Unknown
CVE-2022-39834
Disclosure Date: November 17, 2022 (last updated December 22, 2024)
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.
0
Attacker Value
Unknown
CVE-2022-42954
Disclosure Date: November 17, 2022 (last updated December 22, 2024)
Keyfactor EJBCA before 7.10.0 allows XSS.
0