First published: Thu Jul 28 2022(Updated: )
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/booth | 1.0-162-g27f917f-2+deb10u1 1.0-237-gdd88847-2+deb11u1 1.0-283-g9d4029a-2 1.0-283-g9d4029a-3 | |
Clusterlabs Booth | <=1.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2553 is a vulnerability in the Booth software where the authfile directive in the booth config file is ignored.
CVE-2022-2553 allows nodes without the correct authentication key to communicate with other nodes in the cluster.
CVE-2022-2553 has a severity rating of 6.5 out of 10.
CVE-2022-2553 affects booth versions 1.0-162-g27f917f-2+deb10u1, 1.0-237-gdd88847-2+deb11u1, 1.0-283-g9d4029a-2, and 1.0-283-g9d4029a-3.
To fix CVE-2022-2553, update the booth software to a version that includes the fix.