PT-2022-16358 · Keylime · Keylime
Matthias Gerstner
·
Published
2022-09-21
·
Updated
2022-09-22
·
CVE-2022-23948
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keylime versions prior to 6.3.0
Description
A flaw in the Keylime agent's logic for checking secure mounts can be exploited, allowing secrets to be leaked to other processes on the host. This occurs because previously created unprivileged mounts can fool the secure mount check.
Recommendations
For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information on the host to minimize the risk of secrets being leaked.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keylime