Записи keylime
13 опубликованных записей вендора keylime.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 46,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-290 Authentication Bypass by Spoofing2
- CWE-322 Key Exchange without Entity Authentication1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-379 Creation of Temporary File in Directory with Insecure Permissions1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2026-1709Эксплойта нет | Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authenticationkeylime · keylime · CWE-322 | Критическая9,8 | — | 5,5 % | 6 февр. 2026 г. |
40В плане | CVE-2021-43310Эксплойта нет | A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent werekeylime · keylime · CWE-290 | Критическая9,8 | — | 2,2 % | 21 сент. 2022 г. |
39Наблюдать | CVE-2021-3406Эксплойта нет | A flaw was found in keylime 5.8.1 and older.keylime · keylime · CWE-347 | Критическая9,8 | — | 0,7 % | 25 февр. 2021 г. |
36Наблюдать | CVE-2022-1053Эксплойта нет | Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and tkeylime · keylime · CWE-20 | Критическая9,1 | — | 1,5 % | 6 мая 2022 г. |
30Наблюдать | CVE-2022-23950Эксплойта нет | In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prkeylime · keylime · CWE-379 | Высокая7,5 | — | 1,6 % | 21 сент. 2022 г. |
30Наблюдать | CVE-2023-38200Эксплойта нет | Keylime: registrar is subject to a dos against ssl connectionskeylime · keylime · CWE-400 | Высокая7,5 | — | 1,4 % | 24 июл. 2023 г. |
30Наблюдать | CVE-2022-23948Эксплойта нет | A flaw was found in Keylime before 6.3.0.keylime · keylime · CWE-200 | Высокая7,5 | — | 1,4 % | 21 сент. 2022 г. |
30Наблюдать | CVE-2022-23952Эксплойта нет | In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.keylime · keylime · CWE-200 | Высокая7,5 | — | 1,4 % | 21 сент. 2022 г. |
30Наблюдать | CVE-2022-23949Эксплойта нет | In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.keylime · keylime · CWE-290 | Высокая7,5 | — | 1,4 % | 21 сент. 2022 г. |
26Наблюдать | CVE-2023-38201Эксплойта нет | Keylime: challenge-response protocol bypass during agent registrationkeylime · keylime · CWE-639 | Средняя6,5 | — | 0,5 % | 25 авг. 2023 г. |
22Наблюдать | CVE-2022-23951Эксплойта нет | In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.keylime · keylime · CWE-400 | Средняя5,5 | — | 0,4 % | 21 сент. 2022 г. |
20Наблюдать | CVE-2022-3500Эксплойта нет | A vulnerability was found in keylime.keylime · keylime · CWE-248 | Средняя5,1 | — | 0,3 % | 22 нояб. 2022 г. |
11Наблюдать | CVE-2023-3674Эксплойта нет | Keylime: attestation failure when the quote's signature does not validatekeylime · keylime · CWE-1283 | Низкая2,8 | — | 0,2 % | 19 июл. 2023 г. |
- CVE-2026-170941В плане
Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %keylime · keylime6 февр. 2026 г.
- CVE-2021-4331040В плане
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %keylime · keylime21 сент. 2022 г.
- CVE-2021-340639Наблюдать
A flaw was found in keylime 5.8.1 and older.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %keylime · keylime25 февр. 2021 г.
- CVE-2022-105336Наблюдать
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and t
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %keylime · keylime6 мая 2022 г.
- CVE-2022-2395030Наблюдать
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to pr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %keylime · keylime21 сент. 2022 г.
- CVE-2023-3820030Наблюдать
Keylime: registrar is subject to a dos against ssl connections
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keylime · keylime24 июл. 2023 г.
- CVE-2022-2394830Наблюдать
A flaw was found in Keylime before 6.3.0.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keylime · keylime21 сент. 2022 г.
- CVE-2022-2395230Наблюдать
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keylime · keylime21 сент. 2022 г.
- CVE-2022-2394930Наблюдать
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keylime · keylime21 сент. 2022 г.
- CVE-2023-3820126Наблюдать
Keylime: challenge-response protocol bypass during agent registration
СредняяCVSS 6,5Эксплойта нетEPSS 0 %keylime · keylime25 авг. 2023 г.
- CVE-2022-2395122Наблюдать
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %keylime · keylime21 сент. 2022 г.
- CVE-2022-350020Наблюдать
A vulnerability was found in keylime.
СредняяCVSS 5,1Эксплойта нетEPSS 0 %keylime · keylime22 нояб. 2022 г.
- CVE-2023-367411Наблюдать
Keylime: attestation failure when the quote's signature does not validate
НизкаяCVSS 2,8Эксплойта нетEPSS 0 %keylime · keylime19 июл. 2023 г.