CVE-2022-2553: Medium severity clusterlabs vulnerability
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-2553?
CVE-2022-2553 is a vulnerability in the Booth software where the authfile directive in the booth config file is ignored.
How does CVE-2022-2553 affect the communication between nodes in a cluster?
CVE-2022-2553 allows nodes without the correct authentication key to communicate with other nodes in the cluster.
How severe is CVE-2022-2553?
CVE-2022-2553 has a severity rating of 6.5 out of 10.
Which software versions are affected by CVE-2022-2553?
CVE-2022-2553 affects booth versions 1.0-162-g27f917f-2+deb10u1, 1.0-237-gdd88847-2+deb11u1, 1.0-283-g9d4029a-2, and 1.0-283-g9d4029a-3.
How can I fix CVE-2022-2553?
To fix CVE-2022-2553, update the booth software to a version that includes the fix.