CVE-2021-40087

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
25/08/2021
Last modified:
07/09/2021

Description

An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:* 7.6.0 (excluding)


References to Advisories, Solutions, and Tools