
CVE-2019-14222: Default Certificate in Alfresco Community
Alfresco Community 5.x and below ships by default with a set of known private certificates. Anyone who downloads and installs the Alfresco Community software on a local machine gets access to these files.
Once obtained, these private keys can be used to:
The disclosure for this vulnerability can be found here.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.