Back to search
CVE-2019-13033
Published: Jun 18, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://cisofy.com/security/cve/cve-2019-13033/
x_refsource_CONFIRM
[debian-lts-announce] 20200621 [SECURITY] [DLA 2253-1] lynis security update
mailing-list
x_refsource_MLIST
FEDORA-2020-f251753b0f
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-059e1591d6
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now