CVE-2022-3500
Last modified
CVE-2022-3500 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Keylime | Keylime | < 6.5.1 |
| Redhat | Enterprise Linux | 9.0 |
| Fedoraproject | Fedora | 35 |
| Fedoraproject | Fedora | 36 |
| Fedoraproject | Fedora | 37 |
References
- https://access.redhat.com/security/cve/CVE-2022-3500Third Party Advisory
- https://github.com/keylime/keylime/pull/1128Issue Tracking, Patch, Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-3500Third Party Advisory
- https://github.com/keylime/keylime/pull/1128Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3500?
How severe is CVE-2022-3500?
How do I fix CVE-2022-3500?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-3499An authenticated attacker could utilize the identical agent …6.5
- CVE-2022-34991Paymoney v3.3 was discovered to contain multiple reflected c…5.4
- CVE-2022-34992Luadec v0.9.9 was discovered to contain a heap-buffer overfl…7.8
- CVE-2022-34993Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a …9.8
- CVE-2022-34998JPEGDEC commit be4843c was discovered to contain a global bu…7.8
- CVE-2022-34999JPEGDEC commit be4843c was discovered to contain a FPE via D…5.5
- CVE-2022-35000JPEGDEC commit be4843c was discovered to contain a segmentat…5.5
- CVE-2022-35002JPEGDEC commit be4843c was discovered to contain a segmentat…5.5
- CVE-2022-35003JPEGDEC commit be4843c was discovered to contain a global bu…7.8
- CVE-2022-35004JPEGDEC commit be4843c was discovered to contain a FPE via T…5.5
- CVE-2022-35007PNGDec commit 8abf6be was discovered to contain a heap buffe…6.5
- CVE-2022-35008PNGDec commit 8abf6be was discovered to contain a stack over…6.5
Are you affected by CVE-2022-3500?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
