CVE-2021-44225
Summary
| CVE | CVE-2021-44225 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-26 00:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Application | Keepalived | Keepalived | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 35 Update: keepalived-2.2.4-2.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 34 Update: keepalived-2.2.4-2.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 34 Update: keepalived-2.2.4-2.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| dbus: fix policy to not be overly broad · acassen/keepalived@7977fec · GitHub | MISC | github.com | |
| [SECURITY] Fedora 35 Update: keepalived-2.2.4-2.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| dbus: fix policy to not be overly broad by vincentbernat · Pull Request #2063 · acassen/keepalived · GitHub | MISC | github.com | |
| [SECURITY] [DLA 3388-1] keepalived security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161223 Oracle Enterprise Linux Security Update for keepalived (ELSA-2022-1930)
- 179942 Debian Security Update for keepalived (CVE-2021-44225)
- 181727 Debian Security Update for keepalived (DLA 3388-1)
- 198623 Ubuntu Security Notification for Keepalived Vulnerability (USN-5188-1)
- 240278 Red Hat Update for keepalived (RHSA-2022:1930)
- 282182 Fedora Security Update for keepalived (FEDORA-2021-255eff1bb5)
- 282183 Fedora Security Update for keepalived (FEDORA-2021-0cda131052)
- 354447 Amazon Linux Security Advisory for keepalived : ALAS2022-2022-038
- 355695 Amazon Linux Security Advisory for keepalived : ALAS2-2023-2168
- 502312 Alpine Linux Security Update for keepalived
- 671383 EulerOS Security Update for keepalived (EulerOS-SA-2022-1307)
- 671391 EulerOS Security Update for keepalived (EulerOS-SA-2022-1291)
- 671433 EulerOS Security Update for keepalived (EulerOS-SA-2022-1351)
- 671502 EulerOS Security Update for keepalived (EulerOS-SA-2022-1465)
- 671523 EulerOS Security Update for keepalived (EulerOS-SA-2022-1474)
- 671649 EulerOS Security Update for keepalived (EulerOS-SA-2022-1734)
- 753311 SUSE Enterprise Linux Security Update for keepalived (SUSE-SU-2022:3232-1)
- 753382 SUSE Enterprise Linux Security Update for keepalived (SUSE-SU-2022:2923-1)
- 900455 Common Base Linux Mariner (CBL-Mariner) Security Update for keepalived (6287)
- 901889 Common Base Linux Mariner (CBL-Mariner) Security Update for keepalived (6508-1)
- 940516 AlmaLinux Security Update for keepalived (ALSA-2022:1930)
- 960129 Rocky Linux Security Update for keepalived (RLSA-2022:1930)