SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-2623

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering.

MEDIUM 5.3EPSS 1.03%

Does this matter?

Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.

Description

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
rpm-ostree/rpm-ostree · rpm-ostree/rpm-ostree-client · redhat/enterprise linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.