CVE-2022-3500
published 2022-11-22CVE-2022-3500: A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the…
medium5.1CVSS 3.1
AVLACHPRNUINSUCNINAH
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| keylime | keylime | < 6.5.1 | 6.5.1 |
| keylime | keylime | — | — |
| keylime | keylime | >= 0 < 6.5.1 | 6.5.1 |
| redhat | enterprise_linux | — | — |
OSV
CVE-2022-3500: A vulnerability was found in keylime
osv·2022-11-22
CVE-2022-3500 CVE-2022-3500: A vulnerability was found in keylime
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.
OSV
Keylime: unhandled exceptions could lead to invalid attestation states
osv·2022-10-28
CVE-2022-3500 [HIGH] Keylime: unhandled exceptions could lead to invalid attestation states
Keylime: unhandled exceptions could lead to invalid attestation states
### Impact
This vulnerability creates a false sense of security for keylime users -- i.e. a user could query keylime and conclude that a parcitular node/agent is correctly attested, while attestations are not in fact taking place.
**Short explanation**: the keylime verifier creates periodic reports on the state of each attested agent. The keylime verifier runs a set of python asynchronous processes to challenge attested nodes and create reports on the outcome.
The vulnerability consists of the above named python asynchronous processes failing silently, i.e. quitting without leaving behind a database entry, raising an error or producing even a mention of an error in a log. The silent failure can be triggered by a sma
GHSA
Keylime: unhandled exceptions could lead to invalid attestation states
ghsa·2022-10-28
CVE-2022-3500 [HIGH] CWE-248 Keylime: unhandled exceptions could lead to invalid attestation states
Keylime: unhandled exceptions could lead to invalid attestation states
### Impact
This vulnerability creates a false sense of security for keylime users -- i.e. a user could query keylime and conclude that a parcitular node/agent is correctly attested, while attestations are not in fact taking place.
**Short explanation**: the keylime verifier creates periodic reports on the state of each attested agent. The keylime verifier runs a set of python asynchronous processes to challenge attested nodes and create reports on the outcome.
The vulnerability consists of the above named python asynchronous processes failing silently, i.e. quitting without leaving behind a database entry, raising an error or producing even a mention of an error in a log. The silent failure can be triggered by a sma
Red Hat
keylime: exception handling and impedance match in tornado_requests
vendor_redhat·2022-10-27·CVSS 5.1
CVE-2022-3500 [MEDIUM] CWE-248 keylime: exception handling and impedance match in tornado_requests
keylime: exception handling and impedance match in tornado_requests
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.
A vulnerability was found in keylime. This issue occurs due to improperly handled exceptions. A rogue agent could potentially create errors on the verifier that stopped attestation attempts for that host, leaving it in an attested state but not verified.
No detection rules found.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-3500https://github.com/keylime/keylime/pull/1128https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PUTHMDVFNGGVPCNPOGULMJAAFEP7MEXP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QX4XVCAUFGJ2I2NCTOKONTJGRJB2NBBT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQH5CJRX65QYMQN5WGUKKKE3IRJBWG5Z/https://access.redhat.com/security/cve/CVE-2022-3500https://github.com/keylime/keylime/pull/1128https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PUTHMDVFNGGVPCNPOGULMJAAFEP7MEXP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QX4XVCAUFGJ2I2NCTOKONTJGRJB2NBBT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQH5CJRX65QYMQN5WGUKKKE3IRJBWG5Z/
2022-11-22
Published