First published: Wed Sep 21 2022(Updated: )
A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivileged mounts allowing secrets to be leaked to other processes on the host.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Keylime Keylime | <6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23948 is a vulnerability in Keylime before version 6.3.0 that allows secrets to be leaked to other processes on the host.
The severity of CVE-2022-23948 is high with a CVSS score of 7.5.
Keylime versions up to and excluding 6.3.0 are affected by CVE-2022-23948.
To fix CVE-2022-23948, upgrade to Keylime version 6.3.0 or later.
More information about CVE-2022-23948 can be found at the following links: [Link 1](https://github.com/keylime/keylime/commit/1a4f31a6368d651222683c9debe7d6832db6f607), [Link 2](https://github.com/keylime/keylime/commit/d37c406e69cb6689baa2fb7964bad75209703724), [Link 3](https://github.com/keylime/keylime/security/advisories/GHSA-wj36-qcfg-5j52).