keylime@7.12.0 vulnerabilities

TPM-based key bootstrapping and system integrity measurement system for cloud

  • latest version

    7.12.1

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    8 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the keylime package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Validation of Specified Type of Input

    keylime is a TPM-based key bootstrapping and system integrity measurement system for cloud

    Affected versions of this package are vulnerable to Improper Validation of Specified Type of Input due to the registrar process. An attacker can cause the application to fail by populating the database with multiple valid agent registrations with different UUIDs while the version is still below 7.12.0. Then, upon updating to version 7.12.0, any query to the database matching any of the entries populated by the attacker will result in failure.

    How to fix Improper Validation of Specified Type of Input?

    Upgrade keylime to version 7.12.1 or higher.

    [7.12.0,7.12.1)