Booth Clusterlabs Booth

Do you want an email whenever new security vulnerabilities are reported in Clusterlabs Booth?

By the Year

In 2024 there have been 1 vulnerability in Clusterlabs Booth with an average score of 5.9 out of ten. Booth did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2024 as compared to last year.

Year Vulnerabilities Average Score
2024 1 5.90
2023 0 0.00
2022 1 6.50
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Booth vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Clusterlabs Booth Security Vulnerabilities

A flaw was found in Booth, a cluster ticket manager

CVE-2024-3049 5.9 - Medium - June 06, 2024

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

Insufficient Verification of Data Authenticity

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node

CVE-2022-2553 6.5 - Medium - July 28, 2022

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

authentification

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Fedora Project Fedora or by Clusterlabs? Click the Watch button to subscribe.

Clusterlabs
Vendor

subscribe