CVE-2021-44225

Name
CVE-2021-44225
Description
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3d
MISC https://github.com/acassen/keepalived/pull/2063
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5226RYNMNB7FL4MSJDIBBGPUWH6LMRYV/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6O2R6EXURJQFPFPYFWRCZLUYVWQCLSZM/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:keepalived:keepalived:*:*:*:*:*:*:*:* keepalived >= None <= 2.2.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
keepalived 3.14-community 2.2.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
keepalived 3.15-community 2.2.4-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable