Impact
An issue exists in Keyfactor SignServer versions before 7.6.0. When the ATTRIBUTESFILE parameter of the PKCS11CryptoToken is set to a readable file that is not a recognized attribute file, the token throws an exception. The exception handling logs the error message together with the complete content of that file to the application server log. An operator with SignServer administrative privileges and access to the server logs—either locally or via a remote syslog sink—can thus read arbitrary file contents that the local account used by the JBoss process can access.
Affected Systems
The vulnerability affects installations of Keyfactor SignServer that are configured with PKCS11CryptoToken and have ATTRIBUTESFILE pointing to a readable but non‑accepted file. The issue exists in all releases of SignServer prior to 7.6.0; later releases have fixed the handling of ATTRIBUTESFILE. Therefore any deployment running SignServer 7.5.x or earlier and using this configuration is potentially exposed.
Risk and Exploitability
Exploitation requires the attacker to possess SignServer administrative privileges and to be able to read the application server logs. The CVSS score of 4.9 indicates low severity. EPSS indicates a very low probability (<1 %), and the vulnerability is not listed in the CISA KEV catalog. However, environments that expose logs externally—such as through remote syslog shipping—or that lack strict log‑access controls at the operating‑system level may allow an insider or a compromised local user to capture sensitive file data. The impact is a confidentiality compromise of files readable by the JBoss user.
OpenCVE Enrichment