CVE-2022-3500

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2022
Last modified:
29/04/2025

Description

A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:* 6.5.1 (excluding)
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*