CVE Vulnerabilities

CVE-2024-3049

Insufficient Verification of Data Authenticity

Published: Jun 06, 2024 | Modified: Jul 09, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Booth Clusterlabs * 1.1 (excluding)
Red Hat Enterprise Linux 8 RedHat booth-0:1.1-1.el8_10.1 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat booth-0:1.0-199.1.ac1d34c.git.el8_4.2 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat booth-0:1.0-199.1.ac1d34c.git.el8_4.2 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat booth-0:1.0-199.1.ac1d34c.git.el8_6.2 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat booth-0:1.0-199.1.ac1d34c.git.el8_6.2 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat booth-0:1.0-283.1.9d4029a.git.el8_8.1 *
Red Hat Enterprise Linux 9 RedHat booth-0:1.1-1.el9_4.1 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat booth-0:1.0-251.3.bfb2f92.git.el9_0.2 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat booth-0:1.0-283.1.9d4029a.git.el9_2.1 *
Booth Ubuntu mantic *

References