Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
Description
Published to the GitHub Advisory Database
Aug 1, 2023
Reviewed
Aug 1, 2023
Last updated
Sep 4, 2023
Impact
Keylime
registraris prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port8891) blocking further, legitimate connections. As long as the connection is open, theregistraris blocked and cannot serve any further clients (agentsandtenants), which prevents normal operation. The problem does not affect theverifier.Patches
Users should upgrade to release 7.4.0
References