cbcvebase.
CVE-2021-44225
published 2021-11-26

CVE-2021-44225: In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property…

PriorityP429medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
1.16%
63.5th percentile
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

Affected

14 ranges
VendorProductVersion rangeFixed in
debiankeepalived< keepalived 1:2.2.4-0.2 (bookworm)keepalived 1:2.2.4-0.2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
keepalivedkeepalived<= 2.2.4
keepalivedkeepalived>= 0 < 1:2.1.5-0.2+deb11u11:2.1.5-0.2+deb11u1
keepalivedkeepalived>= 0 < 1:2.2.4-0.21:2.2.4-0.2
keepalivedkeepalived>= 0 < 1:2.2.4-0.21:2.2.4-0.2
keepalivedkeepalived>= 0 < 1:2.2.4-0.21:2.2.4-0.2
msrccbl2_keepalived_2.2.7-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_keepalived_2.0.10-7_on_cbl_mariner_1.0

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.