CVE-2025-47221
MEDIUMKeyfactor SignServer < 7.3.1 - Authenticated Arbitrary File Write via Archive Configuration Properties
Title source: llmDescription
An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even ones that will point to files that already exist. This vulnerability gives a user with admin access the possibility to write files in arbitrary directories in the server file system and potentially overwrite files accessible by the local user JBoss.
References (3)
Core 3
Core References
Various Sources
https://support.keyfactor.com/hc/en-us/articles/37639116791067-SignServer-CVE-2025-47221-Arbitrary-file-write
Product
https://support.keyfactor.com
Scores
CVSS v3
5.3
EPSS
0.0022
EPSS Percentile
11.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (1)
keyfactor/signserver
< 7.3.1
Published
Nov 13, 2025
Tracked Since
Feb 18, 2026