Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-44225

Опубликовано: 26 нояб. 2021
Источник: debian
EPSS Низкий

Описание

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keepalivedfixed1:2.2.4-0.2package
keepalivedfixed1:2.1.5-0.2+deb11u1bullseyepackage
keepalivedno-dsastretchpackage

Примечания

  • https://github.com/acassen/keepalived/pull/2063

  • https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3d

EPSS

Процентиль: 16%
0.00053
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 3 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 7.5
redhat
больше 3 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 5.4
nvd
больше 3 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 5.4
msrc
больше 3 лет назад

Описание отсутствует

suse-cvrf
почти 3 года назад

Security update for keepalived

EPSS

Процентиль: 16%
0.00053
Низкий