CVE Vulnerabilities

CVE-2022-1049

Improper Authentication

Published: Mar 25, 2022 | Modified: Dec 14, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Pcs Clusterlabs * 0.11.2 (including)
Red Hat Enterprise Linux 8 RedHat pcs-0:0.10.14-5.el8 *
Red Hat Enterprise Linux 9 RedHat pcs-0:0.11.3-4.el9 *
Pcs Ubuntu bionic *
Pcs Ubuntu esm-apps/bionic *
Pcs Ubuntu esm-apps/focal *
Pcs Ubuntu esm-apps/jammy *
Pcs Ubuntu esm-apps/xenial *
Pcs Ubuntu focal *
Pcs Ubuntu impish *
Pcs Ubuntu jammy *
Pcs Ubuntu trusty *
Pcs Ubuntu xenial *

Potential Mitigations

References