CVE-2022-1049

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clusterlabs:pcs:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

12 Feb 2023, 22:15

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:7935', 'name': 'https://access.redhat.com/errata/RHSA-2022:7935', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=2066629', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=2066629', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2022-1049', 'name': 'https://access.redhat.com/security/cve/CVE-2022-1049', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5/', 'name': 'https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5/', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:7447', 'name': 'https://access.redhat.com/errata/RHSA-2022:7447', 'tags': [], 'refsource': 'MISC'}
Summary A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon allowed expired accounts and accounts with expired passwords to log in when using PAM authentication. Unprivileged, expired accounts with previously denied access could still log in. A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.

02 Feb 2023, 21:22

Type Values Removed Values Added
Summary A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login. A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon allowed expired accounts and accounts with expired passwords to log in when using PAM authentication. Unprivileged, expired accounts with previously denied access could still log in.
References
  • (MISC) https://access.redhat.com/errata/RHSA-2022:7935 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2066629 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2022-1049 -
  • (MISC) https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5/ -
  • (MISC) https://access.redhat.com/errata/RHSA-2022:7447 -

27 Oct 2022, 16:11

Type Values Removed Values Added
First Time Debian debian Linux
Debian
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
References (MLIST) https://lists.debian.org/debian-lts-announce/2022/09/msg00017.html - (MLIST) https://lists.debian.org/debian-lts-announce/2022/09/msg00017.html - Mailing List, Third Party Advisory
References (DEBIAN) https://www.debian.org/security/2022/dsa-5226 - (DEBIAN) https://www.debian.org/security/2022/dsa-5226 - Third Party Advisory

15 Sep 2022, 00:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2022/09/msg00017.html -

07 Sep 2022, 04:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2022/dsa-5226 -

31 Mar 2022, 14:59

Type Values Removed Values Added
References (MISC) https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5 - (MISC) https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5 - Exploit, Third Party Advisory
CPE cpe:2.3:a:clusterlabs:pcs:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CWE CWE-287
First Time Clusterlabs
Clusterlabs pcs

25 Mar 2022, 19:44

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-25 19:15

Updated : 2023-12-14 21:40


NVD link : CVE-2022-1049

Mitre link : CVE-2022-1049

CVE.ORG link : CVE-2022-1049


JSON object : View

Products Affected

debian

  • debian_linux

clusterlabs

  • pcs
CWE
CWE-287

Improper Authentication