keylime kayıtları
keylime üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %46,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-290 Authentication Bypass by Spoofing2
- CWE-322 Key Exchange without Entity Authentication1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-379 Creation of Temporary File in Directory with Insecure Permissions1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2026-1709İstismar yok | Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authenticationkeylime · keylime · CWE-322 | Kritik9,8 | — | %5,5 | 6 Şub 2026 |
40Planlayın | CVE-2021-43310İstismar yok | A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent werekeylime · keylime · CWE-290 | Kritik9,8 | — | %2,2 | 21 Eyl 2022 |
39İzleyin | CVE-2021-3406İstismar yok | A flaw was found in keylime 5.8.1 and older.keylime · keylime · CWE-347 | Kritik9,8 | — | %0,7 | 25 Şub 2021 |
36İzleyin | CVE-2022-1053İstismar yok | Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and tkeylime · keylime · CWE-20 | Kritik9,1 | — | %1,5 | 6 May 2022 |
30İzleyin | CVE-2022-23950İstismar yok | In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prkeylime · keylime · CWE-379 | Yüksek7,5 | — | %1,6 | 21 Eyl 2022 |
30İzleyin | CVE-2023-38200İstismar yok | Keylime: registrar is subject to a dos against ssl connectionskeylime · keylime · CWE-400 | Yüksek7,5 | — | %1,4 | 24 Tem 2023 |
30İzleyin | CVE-2022-23948İstismar yok | A flaw was found in Keylime before 6.3.0.keylime · keylime · CWE-200 | Yüksek7,5 | — | %1,4 | 21 Eyl 2022 |
30İzleyin | CVE-2022-23952İstismar yok | In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.keylime · keylime · CWE-200 | Yüksek7,5 | — | %1,4 | 21 Eyl 2022 |
30İzleyin | CVE-2022-23949İstismar yok | In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.keylime · keylime · CWE-290 | Yüksek7,5 | — | %1,4 | 21 Eyl 2022 |
26İzleyin | CVE-2023-38201İstismar yok | Keylime: challenge-response protocol bypass during agent registrationkeylime · keylime · CWE-639 | Orta6,5 | — | %0,5 | 25 Ağu 2023 |
22İzleyin | CVE-2022-23951İstismar yok | In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.keylime · keylime · CWE-400 | Orta5,5 | — | %0,4 | 21 Eyl 2022 |
20İzleyin | CVE-2022-3500İstismar yok | A vulnerability was found in keylime.keylime · keylime · CWE-248 | Orta5,1 | — | %0,3 | 22 Kas 2022 |
11İzleyin | CVE-2023-3674İstismar yok | Keylime: attestation failure when the quote's signature does not validatekeylime · keylime · CWE-1283 | Düşük2,8 | — | %0,2 | 19 Tem 2023 |
- CVE-2026-170941Planlayın
Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
KritikCVSS 9,8İstismar yokEPSS %6keylime · keylime6 Şub 2026
- CVE-2021-4331040Planlayın
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were
KritikCVSS 9,8İstismar yokEPSS %2keylime · keylime21 Eyl 2022
- CVE-2021-340639İzleyin
A flaw was found in keylime 5.8.1 and older.
KritikCVSS 9,8İstismar yokEPSS %1keylime · keylime25 Şub 2021
- CVE-2022-105336İzleyin
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and t
KritikCVSS 9,1İstismar yokEPSS %1keylime · keylime6 May 2022
- CVE-2022-2395030İzleyin
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to pr
YüksekCVSS 7,5İstismar yokEPSS %2keylime · keylime21 Eyl 2022
- CVE-2023-3820030İzleyin
Keylime: registrar is subject to a dos against ssl connections
YüksekCVSS 7,5İstismar yokEPSS %1keylime · keylime24 Tem 2023
- CVE-2022-2394830İzleyin
A flaw was found in Keylime before 6.3.0.
YüksekCVSS 7,5İstismar yokEPSS %1keylime · keylime21 Eyl 2022
- CVE-2022-2395230İzleyin
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.
YüksekCVSS 7,5İstismar yokEPSS %1keylime · keylime21 Eyl 2022
- CVE-2022-2394930İzleyin
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
YüksekCVSS 7,5İstismar yokEPSS %1keylime · keylime21 Eyl 2022
- CVE-2023-3820126İzleyin
Keylime: challenge-response protocol bypass during agent registration
OrtaCVSS 6,5İstismar yokEPSS %0keylime · keylime25 Ağu 2023
- CVE-2022-2395122İzleyin
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
OrtaCVSS 5,5İstismar yokEPSS %0keylime · keylime21 Eyl 2022
- CVE-2022-350020İzleyin
A vulnerability was found in keylime.
OrtaCVSS 5,1İstismar yokEPSS %0keylime · keylime22 Kas 2022
- CVE-2023-367411İzleyin
Keylime: attestation failure when the quote's signature does not validate
DüşükCVSS 2,8İstismar yokEPSS %0keylime · keylime19 Tem 2023