NA

CVE-2022-2553

Published: 28/07/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clusterlabs booth

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Synopsis Moderate: booth security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for booth is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a securi ...
Synopsis Moderate: booth security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for booth is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a securi ...
Synopsis Moderate: booth security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for booth is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product Security has rated this ...
It was discovered that Booth, a cluster ticket manager, didn't correctly restrict intra-node communication when configuring the authfile configuration directive For the oldstable distribution (buster), this problem has been fixed in version 10-162-g27f917f-2+deb10u1 For the stable distribution (bullseye), this problem has been fixed in version 1 ...
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster (CVE-2022-2553) ...