Описание
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
Отчет
This issue did not affect the versions of edk2/ovmf as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include support for HTTP boot nor TLS. Compile time options HTTP_BOOT_ENABLE and TLS_ENABLE are both disabled in the shipped packages.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | ovmf | Not affected | ||
Red Hat Enterprise Linux 8 | edk2 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
Improper authentication in EDK II may allow a privileged user to poten ...
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
Уязвимость среды с открытым исходным кодом для разработки UEFI EDK2, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
7.5 High
CVSS3