Permissions, Privileges, and Access Controls in booth (Debian package) - CVE-2022-2553
Published: August 1, 2022
Vulnerability identifier: #VU65903
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2553
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass certain security restrictions.
The vulnerability exists due to application does not properly restrict intra-node communication when configuring the authfile
configuration directive. A remote node with incorrect authentication key can continue communication with the other node members.
Affected software
booth (Debian package)
booth-debuginfo
booth-debugsource
booth
booth (Ubuntu package)
booth-test
booth-site
booth-arbitrator
booth-core
booth (Red Hat package)
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Anolis OS
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Availability GEO
SUSE Linux Enterprise High Availability
openSUSE Leap
Ubuntu
Fedora
booth-debuginfo
booth-debugsource
booth
booth (Ubuntu package)
booth-test
booth-site
booth-arbitrator
booth-core
booth (Red Hat package)
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Anolis OS
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Availability GEO
SUSE Linux Enterprise High Availability
openSUSE Leap
Ubuntu
Fedora
How to mitigate CVE-2022-2553
Install updates from vendor's website.
booth (Debian package) - addressed in versions 1.0-162-g27f917f-2+deb10u1, 1.0-237-gdd88847-2+deb11u1
booth-debuginfo - addressed in versions 1.0-42.3.1, 1.0-150000.6.3.1, 1.0-150100.11.3.1, 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
booth-debugsource - addressed in versions 1.0-42.3.1, 1.0-150000.6.3.1, 1.0-150100.11.3.1, 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
booth - addressed in versions 1.0-42.3.1, 1.0-150000.6.3.1, 1.0-150100.11.3.1, 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
booth (Ubuntu package) - addressed in versions 1.0-174-gce9f821-1ubuntu0.2, 1.0-237-gdd88847-4ubuntu2.2
booth-test - update to 1.0-199.1.ac1d34c.git
booth-site - update to 1.0-199.1.ac1d34c.git
booth-arbitrator - update to 1.0-199.1.ac1d34c.git
booth-core - update to 1.0-199.1.ac1d34c.git
booth - update to 1.0-199.1.ac1d34c.git
booth (Red Hat package) - addressed in versions 1.0-199.1.ac1d34c.git.el8_4.1, 1.0-199.1.ac1d34c.git.el8_6.1, 1.0-251.3.bfb2f92.git.el9_0.1
booth - addressed in versions 1.0-251.3.bfb2f92.git.fc35, 1.0-251.4.bfb2f92.git.fc35, 1.0-262.2.d0ac26c.git.fc36, 1.0-262.3.d0ac26c.git.fc36
booth-test - addressed in versions 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
booth-debuginfo - addressed in versions 1.0-42.3.1, 1.0-150000.6.3.1, 1.0-150100.11.3.1, 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
booth-debugsource - addressed in versions 1.0-42.3.1, 1.0-150000.6.3.1, 1.0-150100.11.3.1, 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
booth - addressed in versions 1.0-42.3.1, 1.0-150000.6.3.1, 1.0-150100.11.3.1, 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
booth (Ubuntu package) - addressed in versions 1.0-174-gce9f821-1ubuntu0.2, 1.0-237-gdd88847-4ubuntu2.2
booth-test - update to 1.0-199.1.ac1d34c.git
booth-site - update to 1.0-199.1.ac1d34c.git
booth-arbitrator - update to 1.0-199.1.ac1d34c.git
booth-core - update to 1.0-199.1.ac1d34c.git
booth - update to 1.0-199.1.ac1d34c.git
booth (Red Hat package) - addressed in versions 1.0-199.1.ac1d34c.git.el8_4.1, 1.0-199.1.ac1d34c.git.el8_6.1, 1.0-251.3.bfb2f92.git.el9_0.1
booth - addressed in versions 1.0-251.3.bfb2f92.git.fc35, 1.0-251.4.bfb2f92.git.fc35, 1.0-262.2.d0ac26c.git.fc36, 1.0-262.3.d0ac26c.git.fc36
booth-test - addressed in versions 1.0-150300.18.3.1, 1.0+20210519.bfb2f92-150400.3.3.1
External References
Related Security Bulletins
- Debian update for booth
- SUSE update for booth
- SUSE update for booth
- SUSE update for booth
- SUSE update for booth
- SUSE update for booth
- Red Hat Enterprise Linux High Availability 8.4 update for booth
- Red Hat Enterprise Linux High Availability 8 update for booth
- Red Hat Enterprise Linux High Availability 9 update for booth
- Ubuntu update for booth
- Fedora 35 update for booth
- Fedora 36 update for booth
- Fedora 36 update for booth
- Fedora 35 update for booth
- Anolis OS update for booth