PT-2022-16363 · Keylime · Keylime

Matthias Gerstner

·

Published

2022-09-21

·

Updated

2022-09-22

·

CVE-2022-23952

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keylime versions prior to 6.3.0
Description The issue concerns the installation of the keylime.conf file by the Keylime installer, which contains sensitive data and is installed as world-readable.
Recommendations For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the keylime.conf file to prevent unauthorized reading of sensitive data.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23952
GHSA-FCHM-5W2V-QFM8
OPENSUSE-SU-2024:11785-1

Affected Products

Keylime