Skip to content
Noroxi

keylime records

13 published records for vendor keylime.

All records

13 records
  • Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication

    CriticalCVSS 9.8No exploitEPSS 6%

    keylime · keylimeFeb 6, 2026

  • A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were

    CriticalCVSS 9.8No exploitEPSS 2%

    keylime · keylimeSep 21, 2022

  • CVE-2021-3406
    39Monitor

    A flaw was found in keylime 5.8.1 and older.

    CriticalCVSS 9.8No exploitEPSS 1%

    keylime · keylimeFeb 25, 2021

  • CVE-2022-1053
    36Monitor

    Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and t

    CriticalCVSS 9.1No exploitEPSS 1%

    keylime · keylimeMay 6, 2022

  • In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to pr

    HighCVSS 7.5No exploitEPSS 2%

    keylime · keylimeSep 21, 2022

  • Keylime: registrar is subject to a dos against ssl connections

    HighCVSS 7.5No exploitEPSS 1%

    keylime · keylimeJul 24, 2023

  • A flaw was found in Keylime before 6.3.0.

    HighCVSS 7.5No exploitEPSS 1%

    keylime · keylimeSep 21, 2022

  • In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.

    HighCVSS 7.5No exploitEPSS 1%

    keylime · keylimeSep 21, 2022

  • In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.

    HighCVSS 7.5No exploitEPSS 1%

    keylime · keylimeSep 21, 2022

  • Keylime: challenge-response protocol bypass during agent registration

    MediumCVSS 6.5No exploitEPSS 0%

    keylime · keylimeAug 25, 2023

  • In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.

    MediumCVSS 5.5No exploitEPSS 0%

    keylime · keylimeSep 21, 2022

  • CVE-2022-3500
    20Monitor

    A vulnerability was found in keylime.

    MediumCVSS 5.1No exploitEPSS 0%

    keylime · keylimeNov 22, 2022

  • CVE-2023-3674
    11Monitor

    Keylime: attestation failure when the quote's signature does not validate

    LowCVSS 2.8No exploitEPSS 0%

    keylime · keylimeJul 19, 2023