← back
CVE-2025-3027

Open Redirect vulnerability in EJBCA

CVSS 5.1 MEDIUMEPSS 0.2%CWE-601
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
31 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnerability could allow users to be redirected to potentially malicious external sites, which can be exploited for phishing or other social engineering attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →