Vulnerabilities > Keylime > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-24 CVE-2023-38200 Excessive Iteration vulnerability in multiple products
A flaw was found in Keylime.
network
low complexity
keylime redhat fedoraproject CWE-834
7.5
2022-09-21 CVE-2022-23948 Unspecified vulnerability in Keylime
A flaw was found in Keylime before 6.3.0.
network
low complexity
keylime
7.5
2022-09-21 CVE-2022-23949 Authentication Bypass by Spoofing vulnerability in Keylime
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
network
low complexity
keylime CWE-290
7.5
2022-09-21 CVE-2022-23950 Exposure of Resource to Wrong Sphere vulnerability in Keylime
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.
network
low complexity
keylime CWE-668
7.5
2022-09-21 CVE-2022-23952 Unspecified vulnerability in Keylime
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.
network
low complexity
keylime
7.5