PT-2023-26333 · Keylime+3 · Keylime+3

Flozilla

·

Publicado

2023-07-24

·

Atualizado

2024-09-16

·

CVE-2023-38200

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Keylime versions prior to 7.4.0
Description A flaw was found in Keylime due to its blocking nature, making the Keylime registrar subject to a remote denial of service against its SSL connections. This allows an attacker to exhaust all available connections, preventing normal operation. The issue affects the registrar component, blocking further legitimate connections, but does not affect the verifier. The problem can be exploited by opening a connection to the TLS port, by default port 8891, which blocks the registrar and prevents it from serving clients, including agents and tenants.
Recommendations For versions prior to 7.4.0, users should upgrade to release 7.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the TLS port, by default port 8891, to minimize the risk of exploitation. Additionally, users can consider disabling the registrar component until the upgrade is applied.

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:5080
CVE-2023-38200
GHSA-9GJG-834P-5GVV
GHSA-PG75-V6FP-8Q59
OPENSUSE-SU-2023_3245-1
OPENSUSE-SU-2024:13096-1
RHSA-2023:5080
RHSA-2023_5080
SUSE-SU-2023:3245-1
SUSE-SU-2023_3245-1

Produtos afetados

Almalinux
Keylime
Red Hat
Suse