CVE-2023-34196: Keyfactor Ejbca
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.
Affected products
- Keyfactor Ejbca: before 8.0.0 (fixed in 8.0.0)
Published 2023-08-03. Last modified 2026-06-17.