CVE-2023-34196

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
03/08/2023
Last modified:
08/08/2023

Description

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:keyfactor:ejbca:*:*:*:*:*:*:*:* 8.0.0 (excluding)