CVE-2021-44225 - log back

CVE-2021-44225 edited at 26 Nov 2021 08:43:54
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Access restriction bypass
Description
+ In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property.
References
+ https://github.com/acassen/keepalived/pull/2063
+ https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3d
Notes
CVE-2021-44225 created at 26 Nov 2021 08:42:39