keylime records
13 published records for vendor keylime.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 46.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-290 Authentication Bypass by Spoofing2
- CWE-322 Key Exchange without Entity Authentication1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-379 Creation of Temporary File in Directory with Insecure Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2026-1709No exploit | Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authenticationkeylime · keylime · CWE-322 | Critical9.8 | — | 5.5% | Feb 6, 2026 |
40Plan | CVE-2021-43310No exploit | A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent werekeylime · keylime · CWE-290 | Critical9.8 | — | 2.2% | Sep 21, 2022 |
39Monitor | CVE-2021-3406No exploit | A flaw was found in keylime 5.8.1 and older.keylime · keylime · CWE-347 | Critical9.8 | — | 0.7% | Feb 25, 2021 |
36Monitor | CVE-2022-1053No exploit | Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and tkeylime · keylime · CWE-20 | Critical9.1 | — | 1.5% | May 6, 2022 |
30Monitor | CVE-2022-23950No exploit | In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prkeylime · keylime · CWE-379 | High7.5 | — | 1.6% | Sep 21, 2022 |
30Monitor | CVE-2023-38200No exploit | Keylime: registrar is subject to a dos against ssl connectionskeylime · keylime · CWE-400 | High7.5 | — | 1.4% | Jul 24, 2023 |
30Monitor | CVE-2022-23948No exploit | A flaw was found in Keylime before 6.3.0.keylime · keylime · CWE-200 | High7.5 | — | 1.4% | Sep 21, 2022 |
30Monitor | CVE-2022-23952No exploit | In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.keylime · keylime · CWE-200 | High7.5 | — | 1.4% | Sep 21, 2022 |
30Monitor | CVE-2022-23949No exploit | In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.keylime · keylime · CWE-290 | High7.5 | — | 1.4% | Sep 21, 2022 |
26Monitor | CVE-2023-38201No exploit | Keylime: challenge-response protocol bypass during agent registrationkeylime · keylime · CWE-639 | Medium6.5 | — | 0.5% | Aug 25, 2023 |
22Monitor | CVE-2022-23951No exploit | In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.keylime · keylime · CWE-400 | Medium5.5 | — | 0.4% | Sep 21, 2022 |
20Monitor | CVE-2022-3500No exploit | A vulnerability was found in keylime.keylime · keylime · CWE-248 | Medium5.1 | — | 0.3% | Nov 22, 2022 |
11Monitor | CVE-2023-3674No exploit | Keylime: attestation failure when the quote's signature does not validatekeylime · keylime · CWE-1283 | Low2.8 | — | 0.2% | Jul 19, 2023 |
- CVE-2026-170941Plan
Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
CriticalCVSS 9.8No exploitEPSS 6%keylime · keylimeFeb 6, 2026
- CVE-2021-4331040Plan
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were
CriticalCVSS 9.8No exploitEPSS 2%keylime · keylimeSep 21, 2022
- CVE-2021-340639Monitor
A flaw was found in keylime 5.8.1 and older.
CriticalCVSS 9.8No exploitEPSS 1%keylime · keylimeFeb 25, 2021
- CVE-2022-105336Monitor
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and t
CriticalCVSS 9.1No exploitEPSS 1%keylime · keylimeMay 6, 2022
- CVE-2022-2395030Monitor
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to pr
HighCVSS 7.5No exploitEPSS 2%keylime · keylimeSep 21, 2022
- CVE-2023-3820030Monitor
Keylime: registrar is subject to a dos against ssl connections
HighCVSS 7.5No exploitEPSS 1%keylime · keylimeJul 24, 2023
- CVE-2022-2394830Monitor
A flaw was found in Keylime before 6.3.0.
HighCVSS 7.5No exploitEPSS 1%keylime · keylimeSep 21, 2022
- CVE-2022-2395230Monitor
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.
HighCVSS 7.5No exploitEPSS 1%keylime · keylimeSep 21, 2022
- CVE-2022-2394930Monitor
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
HighCVSS 7.5No exploitEPSS 1%keylime · keylimeSep 21, 2022
- CVE-2023-3820126Monitor
Keylime: challenge-response protocol bypass during agent registration
MediumCVSS 6.5No exploitEPSS 0%keylime · keylimeAug 25, 2023
- CVE-2022-2395122Monitor
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
MediumCVSS 5.5No exploitEPSS 0%keylime · keylimeSep 21, 2022
- CVE-2022-350020Monitor
A vulnerability was found in keylime.
MediumCVSS 5.1No exploitEPSS 0%keylime · keylimeNov 22, 2022
- CVE-2023-367411Monitor
Keylime: attestation failure when the quote's signature does not validate
LowCVSS 2.8No exploitEPSS 0%keylime · keylimeJul 19, 2023