The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulate the generated links and thus redirect the client to a different base URL. In this way, an attacker could insert his own server for the client to send HTTP requests, provided he succeeds in exploiting it.
History

Thu, 09 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Primekey
Primekey ejbca
CPEs cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*
Vendors & Products Primekey
Primekey ejbca
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Mon, 31 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 10:45:00 +0000

Type Values Removed Values Added
Description The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulate the generated links and thus redirect the client to a different base URL. In this way, an attacker could insert his own server for the client to send HTTP requests, provided he succeeds in exploiting it.
Title Improper Neutralization of Special Elements vulnerability in EJBCA
Weaknesses CWE-74
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-03-31T10:30:24.424Z

Updated: 2025-03-31T12:37:40.038Z

Reserved: 2025-03-31T09:23:19.926Z

Link: CVE-2025-3026

cve-icon Vulnrichment

Updated: 2025-03-31T12:37:36.192Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-31T11:15:40.127

Modified: 2025-10-09T15:04:20.607

Link: CVE-2025-3026

cve-icon Redhat

No data.