A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivileged mounts allowing secrets to be leaked to other processes on the host.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: fedora
Published: 2022-09-21T18:23:36
Updated: 2024-08-03T03:59:23.400Z
Reserved: 2022-01-25T00:00:00
Link: CVE-2022-23948
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-21T19:15:09.893
Modified: 2024-11-21T06:49:30.730
Link: CVE-2022-23948
Redhat
No data.