CVE-2022-23950
21.09.2022, 19:15
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.Enginsight
Vendor | Product | Version |
---|---|---|
keylime | keylime | 𝑥 < 6.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-379 - Creation of Temporary File in Directory with Insecure PermissionsThe software creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References