CVE-2022-23948: Infoleak
A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivileged mounts allowing secrets to be leaked to other processes on the host.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-23948?
CVE-2022-23948 is a vulnerability in Keylime before version 6.3.0 that allows secrets to be leaked to other processes on the host.
What is the severity of CVE-2022-23948?
The severity of CVE-2022-23948 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2022-23948?
Keylime versions up to and excluding 6.3.0 are affected by CVE-2022-23948.
How can CVE-2022-23948 be fixed?
To fix CVE-2022-23948, upgrade to Keylime version 6.3.0 or later.
Where can I find more information about CVE-2022-23948?
More information about CVE-2022-23948 can be found at the following links: [Link 1](https://github.com/keylime/keylime/commit/1a4f31a6368d651222683c9debe7d6832db6f607), [Link 2](https://github.com/keylime/keylime/commit/d37c406e69cb6689baa2fb7964bad75209703724), [Link 3](https://github.com/keylime/keylime/security/advisories/GHSA-wj36-qcfg-5j52).