Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pg75-v6fp-8q59

Опубликовано: 01 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Keylime's registrar vulnerable to Denial-of-service attack via a single open connection

Impact

Keylime registrar is prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port 8891) blocking further, legitimate connections. As long as the connection is open, the registrar is blocked and cannot serve any further clients (agents and tenants), which prevents normal operation. The problem does not affect the verifier.

Patches

Users should upgrade to release 7.4.0

Пакеты

Наименование

keylime

pip
Затронутые версииВерсия исправления

< 7.4.0

7.4.0

EPSS

Процентиль: 43%
0.0021
Низкий

7.5 High

CVSS3

Дефекты

CWE-834

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.

CVSS3: 7.5
redhat
около 2 лет назад

A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.

CVSS3: 7.5
nvd
около 2 лет назад

A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.

suse-cvrf
около 2 лет назад

Security update for keylime

oracle-oval
почти 2 года назад

ELSA-2023-5080: keylime security update (MODERATE)

EPSS

Процентиль: 43%
0.0021
Низкий

7.5 High

CVSS3

Дефекты

CWE-834