Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2623

Опубликовано: 27 июл. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 4.3
EPSS Низкий

Описание

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rpm-ostree:rpm-ostree:*:*:*:*:*:*:*:*
Версия до 2017.3 (исключая)
cpe:2.3:a:rpm-ostree:rpm-ostree-client:*:*:*:*:*:*:*:*
Версия до 2017.3 (исключая)
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00263
Низкий

5.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 5.3
redhat
почти 9 лет назад

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

CVSS3: 5.3
github
больше 3 лет назад

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

EPSS

Процентиль: 49%
0.00263
Низкий

5.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-295
CWE-295