Vulnerabilities > CVE-2022-23950 - Exposure of Resource to Wrong Sphere vulnerability in Keylime

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
keylime
CWE-668

Summary

In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.

Common Weakness Enumeration (CWE)