Vulnerability Description
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
CVSS Score
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Keylime | Keylime | < 6.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/keylime/keylime/commit/387e320dc22c89f4f47c68cb37eb9eec2137f3PatchThird Party Advisory
- https://github.com/keylime/keylime/commit/65c2b737129b5837f4a03660aeb1191ced275aPatchThird Party Advisory
- https://github.com/keylime/keylime/commit/e429e95329fc60608713ddfb82f4a92ee3b3d2PatchThird Party Advisory
- https://github.com/keylime/keylime/security/advisories/GHSA-87gh-qc28-j9mmThird Party Advisory
- https://seclists.org/oss-sec/2022/q1/101ExploitMailing ListPatch
- https://github.com/keylime/keylime/commit/387e320dc22c89f4f47c68cb37eb9eec2137f3PatchThird Party Advisory
- https://github.com/keylime/keylime/commit/65c2b737129b5837f4a03660aeb1191ced275aPatchThird Party Advisory
- https://github.com/keylime/keylime/commit/e429e95329fc60608713ddfb82f4a92ee3b3d2PatchThird Party Advisory
- https://github.com/keylime/keylime/security/advisories/GHSA-87gh-qc28-j9mmThird Party Advisory
- https://seclists.org/oss-sec/2022/q1/101ExploitMailing ListPatch
FAQ
What is CVE-2022-23949?
CVE-2022-23949 is a vulnerability with a CVSS score of 7.5 (HIGH). In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
How severe is CVE-2022-23949?
CVE-2022-23949 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23949?
Check the references section above for vendor advisories and patch information. Affected products include: Keylime Keylime.