CVE-2025-47221

A

n arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even ones that will point to files that already exist. This vulnerability gives a user with admin access the possibility to write files in arbitrary directories in the server file system and potentially overwrite files accessible by the local user JBoss.

Configurations

Configuration 1 (hide)

cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:*

History

17 Dec 2025, 20:15

Type Values Removed Values Added
References
  • () https://support.keyfactor.com/hc/en-us/articles/37639116791067-SignServer-CVE-2025-47221-Arbitrary-file-write -
Summary (en) Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 2 of 3. (en) An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even ones that will point to files that already exist. This vulnerability gives a user with admin access the possibility to write files in arbitrary directories in the server file system and potentially overwrite files accessible by the local user JBoss.

24 Nov 2025, 12:26

Type Values Removed Values Added
First Time Keyfactor signserver
Keyfactor
References () https://docs.keyfactor.com/signserver/latest/signserver-7-3-release-notes - () https://docs.keyfactor.com/signserver/latest/signserver-7-3-release-notes - Release Notes
References () https://support.keyfactor.com - () https://support.keyfactor.com - Product
CPE cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:*

14 Nov 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3

14 Nov 2025, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-284

13 Nov 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 21:15

Updated : 2025-12-17 20:15


NVD link : CVE-2025-47221

Mitre link : CVE-2025-47221

CVE.ORG link : CVE-2025-47221


JSON object : View

Products Affected
CWE
CWE-284

Improper Access Control