Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-0567
HistoryJan 16, 2024 - 2:15 p.m.

Design/Logic Flaw

2024-01-1614:15:00
PRIOn knowledge base
www.prio-n.com
9
gnutls
design flaw
cockpit
certificate validation
denial of service
vulnerability

6.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.7%

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

CPENameOperatorVersion
gnutlslt3.8.3