Impact
The vulnerability allows an administrator to set the log file path for SignerStatusReportWorker to any existing file on the server. By pointing the path to a sensitive file, the attacker can overwrite it, potentially disrupting application behavior or enabling further escalation. The file‑write occurs with the same privileges as the local JBoss user, allowing modification of configuration or executable files, representing a path validation flaw (CWE-706).
Affected Systems
Keyfactor SignServer versions prior to 7.6.0 are affected. The issue manifests when the SignerStatusReportWorker component is used to generate a status report and the log file path is not validated for correct location or existence.
Risk and Exploitability
The exploitation requires administrator access to the SignServer configuration. The CVSS score of 2.7 indicates a low severity, and the EPSS score is < 1% with the vulnerability not listed in CISA’s KEV catalog, indicating a very low exploitation probability in the current public landscape. Nonetheless, an attacker who can overwrite arbitrary files could disrupt service availability, tamper withold for further attacks that target files accessible by the JBoss user.
OpenCVE Enrichment