Mutable Attestation or Measurement Reporting Data Affecting keylime package, versions [,7.4.0)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-KEYLIME-5777706
  • published16 Jul 2023
  • disclosed12 Jul 2023
  • creditUnknown

Introduced: 12 Jul 2023

CVE-2023-3674  (opens in a new tab)
CWE-1283  (opens in a new tab)

How to fix?

Upgrade keylime to version 7.4.0 or higher.

Overview

keylime is a TPM-based key bootstrapping and system integrity measurement system for cloud

Affected versions of this package are vulnerable to Mutable Attestation or Measurement Reporting Data due to attestation failure when the quote's signature does not validate. To exploit this vulnerability a non-privileged user would have to modify the keylime agent to create invalid quotes a could then use invalid measurement lists to hide the trust state of a system. The attacker would then have to trick the administrator into using the user's modified keylime agent.

CVSS Scores

version 3.1