CVE-2022-1049: High severity clusterlabs vulnerability
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1049?
CVE-2022-1049 is a vulnerability found in the Pacemaker configuration tool (pcs) that allows expired and expired password accounts to login using PAM authentication.
What is the severity of CVE-2022-1049?
The severity of CVE-2022-1049 is high, with a severity value of 8.8.
How does CVE-2022-1049 affect the software?
CVE-2022-1049 affects systems running pcs version 0.10.1-2 up to and including 0.11.2, as well as ClusterLabs pcs and Debian Debian Linux versions 10.0 and 11.0.
How can I fix CVE-2022-1049?
To fix CVE-2022-1049, upgrade the pcs package to version 0.10.1-2+deb10u1, 0.10.8-1+deb11u1, 0.11.5-1, or 0.11.6-1, depending on your system.
Where can I find more information about CVE-2022-1049?
You can find more information about CVE-2022-1049 at the following references: [link1], [link2], [link3].