Medium severity6.5NVD Advisory· Published Aug 25, 2023· Updated Jun 17, 2026
CVE-2023-38201
CVE-2023-38201
Description
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a breach of the integrity of the registrar database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keylimePyPI | < 7.5.0 | 7.5.0 |
Affected products
22- osv-coords12 versionspkg:rpm/almalinux/keylime-selinuxpkg:rpm/opensuse/keylime&distro=openSUSE%20Leap%2015.5pkg:rpm/almalinux/keylime-tenantpkg:rpm/almalinux/python3-keylimepkg:rpm/suse/keylime&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/opensuse/keylime&distro=openSUSE%20Leap%2015.4pkg:pypi/keylimepkg:rpm/suse/keylime&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/almalinux/keylimepkg:rpm/almalinux/keylime-basepkg:rpm/almalinux/keylime-registrarpkg:rpm/almalinux/keylime-verifier
< 6.5.2-6.el9_2.alma.1+ 11 more
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.3.2-150400.4.20.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.3.2-150400.4.20.1
- (no CPE)range: < 6.3.2-150400.4.20.1
- (no CPE)range: < 7.5.0
- (no CPE)range: < 6.3.2-150400.4.20.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
cpe:/a:redhat:enterprise_linux:9::appstream+ 1 more
- cpe:/a:redhat:enterprise_linux:9::appstreamrange: 0:6.5.2-6.el9_2
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.2_s390x:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.2_ppc64le:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/keylime/keylime/commit/9e5ac9f25cd400b16d5969f531cee28290543f2anvdPatchWEB
- access.redhat.com/errata/RHSA-2023:5080nvdThird Party AdvisoryWEB
- access.redhat.com/security/cve/CVE-2023-38201nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-f4r5-q63f-gcwwghsaADVISORY
- github.com/keylime/keylime/security/advisories/GHSA-f4r5-q63f-gcwwnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-38201ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/keylime/PYSEC-2023-160.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ZIZZB5NHNCS5D2AEH3ZAO6OQC72IK7WSghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ZIZZB5NHNCS5D2AEH3ZAO6OQC72IK7WS/nvd
News mentions
0No linked articles in our index yet.