28-06-2023 22:01
cve-2023-36476 Vulnerabilidad documentada
7.9 HIGH
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users calamares-nixos-extensions version 0.3.12 prior who installed NixOS through the graphical calamares installer, with an unencrypted `/boot`, on either non-UEFI systems or LUKS partition different from `/` have their key file in `/boot` as plaintext CPIO archive attached to initrd. A patch is available anticipated be part 0.3.13 backport 22.11, 23.05, unstable channels. Expert users copy data may, workaround, re-encrypt partition(s) themselves.
http://cwe.mitre.org/data/definitions/200.html CWE-200 Exposure Sensitive Information Unauthorized Actor