Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13033

Опубликовано: 18 июн. 2020
Источник: debian
EPSS Низкий

Описание

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lynisfixed3.0.0-1package

Примечания

  • https://cisofy.com/security/cve/cve-2019-13033/

  • https://github.com/CISOfy/lynis/commit/3b9eda53cc20e851c4456618f027bc9ea794ad30

  • Enabling license system in the packaged version is possible, but enabling it

  • makes little sense as users will end-up quitting on all the extra tests that

  • are not opensourced (and only present in the enterprise version).

EPSS

Процентиль: 22%
0.00072
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 5 лет назад

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.

CVSS3: 3.3
nvd
больше 5 лет назад

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.

CVSS3: 3.3
github
больше 3 лет назад

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.

EPSS

Процентиль: 22%
0.00072
Низкий