CVE-2020-11630

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized.
Configurations

Configuration 1

cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*

Information

Published : 2020-04-08 12:15

Updated : 2020-04-08 07:02


NVD link : CVE-2020-11630

Mitre link : CVE-2020-11630

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data