Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted client auth certificate to connect. Admins can then set more restricted access to specific certificates. A logic error caused this admin CLI command to be run on each restart of the container instead of only the first startup as intended resetting the configuration to "allowany".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Keyfactor SignServer 安全漏洞
Vulnerability Description
Keyfactor SignServer是美国Keyfactor公司的一个数字签名引擎。 Keyfactor SignServer 7.2之前版本存在安全漏洞,该漏洞源于容器启动逻辑错误,可能导致重置配置为allowany。
CVSS Information
N/A
Vulnerability Type
N/A