Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24908
HistoryApr 10, 2020 - 1:09 a.m.

Information Disclosure

2020-04-1001:09:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

21.8%

kexec-tools is vulnerable to information disclosure. Kdump used the SSH (Secure Shell) “StrictHostKeyChecking=no” option when dumping to SSH targets, causing the target kdump server’s SSH host key not to be checked. This could make it easier for a man-in-the-middle attacker on the local network to impersonate the kdump SSH target server and possibly gain access to sensitive information in the vmcore dumps.