keylime
TPM-based key bootstrapping and system integrity measurement system for cloud
Security Advisories for keylime in pypi
Moderate
4 months ago
Keylime has a hardcoded attestation challenge nonce that allows replay attacks
pypi
keylime
Critical
7 months ago
Keylime Missing Authentication for Critical Function and Improper Authentication
pypi
keylime
High
9 months ago
Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices
pypi
keylime
Moderate
over 1 year ago
Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
pypi
keylime
High
almost 3 years ago
Keylime registrar and (untrusted) Agent can be bypassed by an attacker
pypi
keylime
High
about 3 years ago
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
pypi
keylime
Moderate
about 3 years ago
keylime fails to flag device as untrusted when signature does not validate
pypi
keylime
High
almost 4 years ago
Keylime: unhandled exceptions could lead to invalid attestation states
pypi
Keylime