Improper Output Neutralization for Logs in keylime - CVE-2022-23949
Published: January 27, 2022 / Updated: May 7, 2026
keylime
Detailed vulnerability description
The vulnerability allows a remote attacker to spoof log entries.
The vulnerability exists due to improper neutralization of special elements used in a log in verifier and registrar logging when processing agent-supplied UUIDs. A remote attacker can supply a crafted UUID to spoof log entries.
The issue can be triggered by a rogue agent.