Clusterlabs Booth
By the Year
In 2024 there have been 1 vulnerability in Clusterlabs Booth with an average score of 5.9 out of ten. Booth did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2024 as compared to last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 1 | 5.90 |
2023 | 0 | 0.00 |
2022 | 1 | 6.50 |
2021 | 0 | 0.00 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Booth vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Clusterlabs Booth Security Vulnerabilities
A flaw was found in Booth, a cluster ticket manager
CVE-2024-3049
5.9 - Medium
- June 06, 2024
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
Insufficient Verification of Data Authenticity
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node
CVE-2022-2553
6.5 - Medium
- July 28, 2022
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
authentification
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Fedora Project Fedora or by Clusterlabs? Click the Watch button to subscribe.