CVE Vulnerabilities

CVE-2024-0567

Improper Verification of Cryptographic Signature

Published: Jan 16, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
GnutlsGnu3.7.0 (including)3.8.3 (excluding)
Red Hat Enterprise Linux 9RedHatgnutls-0:3.7.6-23.el9_3.3*
Red Hat Enterprise Linux 9RedHatgnutls-0:3.7.6-23.el9_3.3*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatgnutls-0:3.7.6-21.el9_2.2*
RHODF-4.15-RHEL-9RedHatodf4/cephcsi-rhel9:v4.15.0-37*
RHODF-4.15-RHEL-9RedHatodf4/mcg-core-rhel9:v4.15.0-68*
RHODF-4.15-RHEL-9RedHatodf4/mcg-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/mcg-rhel9-operator:v4.15.0-39*
RHODF-4.15-RHEL-9RedHatodf4/ocs-client-console-rhel9:v4.15.0-58*
RHODF-4.15-RHEL-9RedHatodf4/ocs-client-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/ocs-client-rhel9-operator:v4.15.0-13*
RHODF-4.15-RHEL-9RedHatodf4/ocs-metrics-exporter-rhel9:v4.15.0-81*
RHODF-4.15-RHEL-9RedHatodf4/ocs-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/ocs-rhel9-operator:v4.15.0-79*
RHODF-4.15-RHEL-9RedHatodf4/odf-cli-rhel9:v4.15.0-22*
RHODF-4.15-RHEL-9RedHatodf4/odf-console-rhel9:v4.15.0-57*
RHODF-4.15-RHEL-9RedHatodf4/odf-cosi-sidecar-rhel9:v4.15.0-6*
RHODF-4.15-RHEL-9RedHatodf4/odf-csi-addons-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odf-csi-addons-rhel9-operator:v4.15.0-15*
RHODF-4.15-RHEL-9RedHatodf4/odf-csi-addons-sidecar-rhel9:v4.15.0-15*
RHODF-4.15-RHEL-9RedHatodf4/odf-multicluster-console-rhel9:v4.15.0-54*
RHODF-4.15-RHEL-9RedHatodf4/odf-multicluster-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odf-multicluster-rhel9-operator:v4.15.0-10*
RHODF-4.15-RHEL-9RedHatodf4/odf-must-gather-rhel9:v4.15.0-26*
RHODF-4.15-RHEL-9RedHatodf4/odf-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odf-rhel9-operator:v4.15.0-19*
RHODF-4.15-RHEL-9RedHatodf4/odr-cluster-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odr-hub-operator-bundle:v4.15.0-158*
RHODF-4.15-RHEL-9RedHatodf4/odr-rhel9-operator:v4.15.0-21*
RHODF-4.15-RHEL-9RedHatodf4/rook-ceph-rhel9-operator:v4.15.0-103*
RHOL-5.8-RHEL-9RedHatopenshift-logging/cluster-logging-operator-bundle:v5.8.6-22*
RHOL-5.8-RHEL-9RedHatopenshift-logging/cluster-logging-rhel9-operator:v5.8.6-11*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch6-rhel9:v6.8.1-407*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch-operator-bundle:v5.8.6-19*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479*
RHOL-5.8-RHEL-9RedHatopenshift-logging/elasticsearch-rhel9-operator:v5.8.6-7*
RHOL-5.8-RHEL-9RedHatopenshift-logging/eventrouter-rhel9:v0.4.0-247*
RHOL-5.8-RHEL-9RedHatopenshift-logging/fluentd-rhel9:v5.8.6-5*
RHOL-5.8-RHEL-9RedHatopenshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227*
RHOL-5.8-RHEL-9RedHatopenshift-logging/logging-curator5-rhel9:v5.8.1-470*
RHOL-5.8-RHEL-9RedHatopenshift-logging/logging-loki-rhel9:v2.9.6-14*
RHOL-5.8-RHEL-9RedHatopenshift-logging/logging-view-plugin-rhel9:v5.8.6-2*
RHOL-5.8-RHEL-9RedHatopenshift-logging/loki-operator-bundle:v5.8.6-24*
RHOL-5.8-RHEL-9RedHatopenshift-logging/loki-rhel9-operator:v5.8.6-10*
RHOL-5.8-RHEL-9RedHatopenshift-logging/lokistack-gateway-rhel9:v0.1.0-525*
RHOL-5.8-RHEL-9RedHatopenshift-logging/opa-openshift-rhel9:v0.1.0-224*
RHOL-5.8-RHEL-9RedHatopenshift-logging/vector-rhel9:v0.28.1-56*
Gnutls28Ubuntubionic*
Gnutls28Ubuntudevel*
Gnutls28Ubuntujammy*
Gnutls28Ubuntulunar*
Gnutls28Ubuntumantic*
Gnutls28Ubuntunoble*
Gnutls28Ubuntutrusty*
Gnutls28Ubuntuupstream*
Gnutls28Ubuntuxenial*

References