Skip to content

Keylime: Unsanitized UUIDs can lead to log spoofing

High
mpeters published GHSA-87gh-qc28-j9mm Jan 27, 2022

Package

keylime (Keylime)

Affected versions

<6.2.0

Patched versions

6.3.0

Description

Impact

Unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.

Patches

Users should upgrade to at least 6.3.x.

Workarounds

None.

Credit

Many thanks to Matthias Gerstner for finding this issue and for Alberto Planas for the fix.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2022-23949

Weaknesses

No CWEs

Credits