CVE-2022-23949: High severity keylime (keylime) vulnerability
Published Sep 21, 2022
·Updated
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
Affected Software
1 affected component
Keylime Keylime<6.3.0
Remediation
Patch Available
Event History
Sep 21, 2022
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-23949?
CVE-2022-23949 is a vulnerability in Keylime before version 6.3.0 that allows for log spoofing on the verifier and registrar due to unsanitized UUIDs passed by a rogue agent.
2
How does CVE-2022-23949 affect Keylime?
CVE-2022-23949 affects Keylime versions before 6.3.0 and can be exploited by passing unsanitized UUIDs to spoof logs on the verifier and registrar.
3
What is the severity of CVE-2022-23949?
CVE-2022-23949 has a severity rating of 7.5 out of 10 (high severity).
4
How can I fix CVE-2022-23949?
To fix CVE-2022-23949, upgrade Keylime to version 6.3.0 or newer.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-23949?
The Common Weakness Enumeration (CWE) ID for CVE-2022-23949 is CWE-290.