Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is fixed in 0.29.0.
References
Configurations
No configuration.
History
03 Dec 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-03 20:16
Updated : 2025-12-03 20:16
NVD link : CVE-2025-66406
Mitre link : CVE-2025-66406
CVE.ORG link : CVE-2025-66406
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
