First published: Fri Nov 26 2021(Updated: )
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Keepalived Keepalived | <=2.2.4 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
<=2.2.4 | ||
=34 | ||
=35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.