Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2553

Опубликовано: 01 июл. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

A flaw was found in booth in the way it handles the authfile directive in configuration files, which causes authentication to be skipped between nodes. As a result, an attacker-controlled node that does not have the correct authentication key does not prevent communication with other nodes in the cluster.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7boothOut of support scope
Red Hat Enterprise Linux 8boothFixedRHSA-2022:643913.09.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportboothFixedRHSA-2022:625030.08.2022
Red Hat Enterprise Linux 9boothFixedRHSA-2022:658020.09.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2109251booth: authfile directive in booth config file is completely ignored.

EPSS

Процентиль: 43%
0.0021
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

CVSS3: 6.5
nvd
больше 3 лет назад

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

CVSS3: 6.5
msrc
почти 3 года назад

The authfile directive in the booth config file is ignored preventing use of authentication in communications from node to node. As a result nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

CVSS3: 6.5
debian
больше 3 лет назад

The authfile directive in the booth config file is ignored, preventing ...

suse-cvrf
больше 3 лет назад

Security update for booth

EPSS

Процентиль: 43%
0.0021
Низкий

6.5 Medium

CVSS3