CVE-2021-44225: Medium severity red hat keepalived vulnerability
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44225?
CVE-2021-44225 is considered a medium severity vulnerability due to the access-control bypass it introduces.
How do I fix CVE-2021-44225?
To fix CVE-2021-44225, update Keepalived to version 2.2.5 or later.
What systems are affected by CVE-2021-44225?
CVE-2021-44225 affects Keepalived versions up to 2.2.4 and specifically impacted Fedora versions 34 and 35.
What can happen if CVE-2021-44225 is exploited?
Exploiting CVE-2021-44225 can allow unauthorized users to inspect and manipulate properties of unrelated D-Bus system services.
Is CVE-2021-44225 a local or remote vulnerability?
CVE-2021-44225 is primarily a local vulnerability that requires access to the system where Keepalived is running.