cvelist/2021/3xxx/CVE-2021-3406.json

72 lines
2.4 KiB
JSON
Raw Normal View History

2021-02-09 20:00:41 +00:00
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2021-3406",
2021-02-25 20:00:43 +00:00
"ASSIGNER": "secalert@redhat.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "keylime",
"version": {
"version_data": [
{
"version_value": "5.8.1 and older"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-347"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1932469",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1932469"
},
{
"refsource": "MISC",
"name": "https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m",
"url": "https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m"
2021-03-19 22:00:40 +00:00
},
{
"refsource": "FEDORA",
"name": "FEDORA-2021-b7854ccfe4",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/"
2021-02-25 20:00:43 +00:00
}
]
2021-02-09 20:00:41 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2021-02-25 20:00:43 +00:00
"value": "A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations."
2021-02-09 20:00:41 +00:00
}
]
}
}