PT-2023-26333 · Keylime+3 · Keylime+3
Flozilla
·
Publicado
2023-07-24
·
Atualizado
2024-09-16
·
CVE-2023-38200
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Keylime versions prior to 7.4.0
Description
A flaw was found in Keylime due to its blocking nature, making the Keylime registrar subject to a remote denial of service against its SSL connections. This allows an attacker to exhaust all available connections, preventing normal operation. The issue affects the
registrar component, blocking further legitimate connections, but does not affect the verifier. The problem can be exploited by opening a connection to the TLS port, by default port 8891, which blocks the registrar and prevents it from serving clients, including agents and tenants.Recommendations
For versions prior to 7.4.0, users should upgrade to release 7.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the TLS port, by default port
8891, to minimize the risk of exploitation. Additionally, users can consider disabling the registrar component until the upgrade is applied.Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Almalinux
Keylime
Red Hat
Suse