Описание
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
Ссылки
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.8.1 (включая)
cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00104
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-347
CWE-295
EPSS
Процентиль: 29%
0.00104
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-347
CWE-295