Vulnerabilities > CVE-2021-40089 - Unspecified vulnerability in Primekey Ejbca

047910
CVSS 2.3 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
local
low complexity
primekey

Summary

An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to create new such publishers, but existing publishers would continue to run.

Vulnerable Configurations

Part Description Count
Application
Primekey
254