Bugzilla – Bug 1173142
VUL-1: CVE-2019-13033: lynis: the license key can be obtained by looking at the process list when a data upload is being performed
Last modified: 2020-06-19 08:35:03 UTC
CVE-2019-13033 In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-13033 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13033 https://cisofy.com/security/cve/cve-2019-13033/
submitted to tumbleweed