The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade booth-siteUpgrade boothUpgrade booth-coreUpgrade booth-arbitratorUpgrade booth-test | Oct 13, 2022 | Jul 28, 2022 |
| Amazon Linux Ami 2 | — | Upgrade booth-arbitratorUpgrade booth-testUpgrade booth-siteUpgrade booth-debuginfoUpgrade boothUpgrade booth-core | Apr 6, 2023 | Jul 28, 2022 |
| Centos_linux | — | Upgrade booth-arbitratorUpgrade booth-siteUpgrade booth-testUpgrade booth-core-debuginfoUpgrade boothUpgrade booth-debugsourceUpgrade booth-core | Oct 20, 2022 | Jul 28, 2022 |
| Debian | — | Upgrade booth | Aug 17, 2022 | Jul 28, 2022 |
| Redhat_linux | — | Upgrade booth-testUpgrade booth-core-debuginfoUpgrade booth-arbitratorUpgrade booth-siteUpgrade booth-coreNo solution existsUpgrade boothUpgrade booth-debugsource | Oct 20, 2022 | Jul 28, 2022 |
| Rocky_linux | — | Upgrade booth-core-debuginfoUpgrade booth-coreUpgrade booth-debugsourceUpgrade booth | Mar 12, 2024 | Jul 28, 2022 |
| Suse | — | Upgrade booth-testUpgrade booth | Oct 26, 2022 | Jul 28, 2022 |
| Ubuntu | — | Upgrade booth | Mar 22, 2023 | Jul 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub