Metrics
Affected Vendors & Products
Wed, 17 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A file enumeration issue was found in Keyfactor SignServer versions prior to 7.3.2. | A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSigner, can be set to any path without any restrictions by an admin user. In the case that the provided path points to an existing file, readable by the user running the application server, but is not a recognized image format, it will return this as an error to the clientside, confirming the existences of the file. |
| References |
|
Tue, 09 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A file enumeration issue was found in SignServer versions prior to 7.3.2. | A file enumeration issue was found in Keyfactor SignServer versions prior to 7.3.2. |
Tue, 09 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 1 of 3. | A file enumeration issue was found in SignServer versions prior to 7.3.2. |
Mon, 24 Nov 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:* |
Fri, 14 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 14 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Keyfactor
Keyfactor signserver |
|
| Vendors & Products |
Keyfactor
Keyfactor signserver |
Thu, 13 Nov 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 1 of 3. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-17T19:37:06.112Z
Reserved: 2025-05-02T00:00:00.000Z
Link: CVE-2025-47220
Updated: 2025-11-14T16:54:32.963Z
Status : Modified
Published: 2025-11-13T21:15:49.443
Modified: 2025-12-17T20:15:54.960
Link: CVE-2025-47220
No data.
OpenCVE Enrichment
Updated: 2025-11-14T09:29:11Z