{"id":"GHSA-9gjg-834p-5gvv","summary":"Duplicate Advisory: Keylime's registrar vulnerable to Denial-of-service attack via a single open connection","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-pg75-v6fp-8q59. This link is maintained to preserve external references.\n\n## Original Description\nA flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.","modified":"2024-12-03T06:19:55.633792Z","published":"2023-07-24T18:30:44Z","withdrawn":"2023-08-01T20:09:43Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-01T20:09:43Z","nvd_published_at":"2023-07-24T16:15:12Z","cwe_ids":[],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38200"},{"type":"WEB","url":"https://github.com/keylime/keylime/pull/1421"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-38200"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2222692"}],"affected":[{"package":{"name":"keylime","ecosystem":"PyPI","purl":"pkg:pypi/keylime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.0"}]}],"versions":["6.3.1","6.3.2","6.4.0","6.4.1","6.4.2","6.4.3","6.5.0","6.5.1","6.5.2","6.5.3","6.6.0","6.8.0","7.0.0","7.2.5","7.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-9gjg-834p-5gvv/GHSA-9gjg-834p-5gvv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}