CVE-2019-13033
18.06.2020, 18:15
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.Enginsight
Vendor | Product | Version |
---|---|---|
cisofy | lynis | 2.0.0 ≤ 𝑥 ≤ 2.7.5 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References