CVE-2022-23952

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
21/09/2022
Last modified:
22/05/2025

Description

In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:* 6.3.0 (excluding)