It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rpm-ostree-client-debuginfoUpgrade rpm-ostree-clientUpgrade rpm-ostree-debuginfoUpgrade rpm-ostree | Aug 28, 2019 | Jul 27, 2018 |
| Redhat_linux | — | Upgrade rpm-ostree-clientUpgrade rpm-ostree-debuginfoUpgrade rpm-ostree-client-debuginfoUpgrade rpm-ostree | Sep 24, 2018 | Jul 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub