Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-36476

Опубликовано: 29 июн. 2023
Источник: nvd
CVSS3: 7.9
CVSS3: 5.5
EPSS Низкий

Описание

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares installer, with an unencrypted /boot, on either non-UEFI systems or with a LUKS partition different from / have their LUKS key file in /boot as a plaintext CPIO archive attached to their NixOS initrd. A patch is available and anticipated to be part of version 0.3.13 to backport to NixOS 22.11, 23.05, and unstable channels. Expert users who have a copy of their data may, as a workaround, re-encrypt the LUKS partition(s) themselves.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nixos:calamares-nixos-extensions:*:*:*:*:*:*:*:*
Версия до 0.3.13 (исключая)

EPSS

Процентиль: 37%
0.00156
Низкий

7.9 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-522

EPSS

Процентиль: 37%
0.00156
Низкий

7.9 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-522