Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0106 | A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a breach of the integrity of the registrar database. |
Github GHSA |
GHSA-f4r5-q63f-gcww | Keylime registrar and (untrusted) Agent can be bypassed by an attacker |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 16 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T17:41:38.960Z
Reserved: 2023-07-13T13:12:48.728Z
Link: CVE-2023-38201
No data.
Status : Modified
Published: 2023-08-25T17:15:08.530
Modified: 2026-06-17T06:09:39.233
Link: CVE-2023-38201
OpenCVE Enrichment
No data.
-
CWE-639
Authorization Bypass Through User-Controlled Key
- NVD-CWE-noinfo
EUVD
Github GHSA