ALBA-2022:0349

    Dashboard / Vulnerabilities / ALBA-2022:0349

    ALBA-2022:0349

    Published: 1 Feb 2022Last Modified: 2 Feb 2022

    Summary: clevis bug fix and enhancement update

    Details: Clevis is a pluggable framework for automated decryption. It can be used to provide automated decryption of data or even automated unlocking of LUKS volumes. The clevis packages provide the client side of the Network Bound Disk Encryption (NBDE) project. Bug Fix(es) and Enhancement(s): * Server hangs in asking password unless user hits enter in clevis/dracut (BZ#2023256)

    References:

    Affected packages

    Package

    Name: clevis

    Purl: pkg:rpm/almalinux/clevis

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -15-1.el8_5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    ALBA-2022:0349 | CVE-DB