CVE-2022-23952
21.09.2022, 19:15
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| keylime | keylime | 𝑥 < 6.3.0 |
𝑥
= Vulnerable software versions
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| keylime-agent |
| ||||||||||||||||||||||||
| keylime-config |
| ||||||||||||||||||||||||
| keylime-firewalld |
| ||||||||||||||||||||||||
| keylime-logrotate |
| ||||||||||||||||||||||||
| keylime-registrar |
| ||||||||||||||||||||||||
| keylime-tpm_cert_store |
| ||||||||||||||||||||||||
| keylime-verifier |
| ||||||||||||||||||||||||
| python3-keylime |
|
Common Weakness Enumeration
References