CVE-2022-2553
published 2022-07-28CVE-2022-2553: The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.16%
64.0th percentile
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clusterlabs | booth | <= 1.0 | — |
| clusterlabs | booth | — | — |
| clusterlabs | booth | >= 0 < 1.0-237-gdd88847-2+deb11u1 | 1.0-237-gdd88847-2+deb11u1 |
| clusterlabs | booth | >= 0 < 1.0-268-gdce51f9-1 | 1.0-268-gdce51f9-1 |
| clusterlabs | booth | >= 0 < 1.0-268-gdce51f9-1 | 1.0-268-gdce51f9-1 |
| clusterlabs | booth | >= 0 < 1.0-268-gdce51f9-1 | 1.0-268-gdce51f9-1 |
| debian | booth | < booth 1.0-268-gdce51f9-1 (bookworm) | booth 1.0-268-gdce51f9-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_booth_1.0-8_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Booth vulnerability
vendor_ubuntu·2022-08-10
CVE-2022-2553 Booth vulnerability
Title: Booth vulnerability
Summary: Booth could be made to be stop working under certain circuntances.
It was discovered that Booth incorrectly handled user authentication. An
attacker could use this vulnerability to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
The authfile directive in the booth config file is ignored preventing use of authentication in communications from node to node. As a result nodes that do not have the correct authentication key are n
vendor_msrc·2022-07-12·CVSS 6.5
CVE-2022-2553 [MEDIUM] CWE-287 The authfile directive in the booth config file is ignored preventing use of authentication in communications from node to node. As a result nodes that do not have the correct authentication key are n
The authfile directive in the booth config file is ignored preventing use of authentication in communications from node to node. As a result nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If
Red Hat
booth: authfile directive in booth config file is completely ignored.
vendor_redhat·2022-07-01·CVSS 6.5
CVE-2022-2553 [MEDIUM] CWE-287 booth: authfile directive in booth config file is completely ignored.
booth: authfile directive in booth config file is completely ignored.
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
A flaw was found in booth in the way it handles the authfile directive in configuration files, which causes authentication to be skipped between nodes. As a result, an attacker-controlled node that does not have the correct authentication key does not prevent communication with other nodes in the cluster.
Package: booth (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2022-2553: booth - The authfile directive in the booth config file is ignored, preventing use of au...
vendor_debian·2022·CVSS 6.5
CVE-2022-2553 [MEDIUM] CVE-2022-2553: booth - The authfile directive in the booth config file is ignored, preventing use of au...
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
Scope: local
bookworm: resolved (fixed in 1.0-268-gdce51f9-1)
bullseye: resolved (fixed in 1.0-237-gdd88847-2+deb11u1)
forky: resolved (fixed in 1.0-268-gdce51f9-1)
sid: resolved (fixed in 1.0-268-gdce51f9-1)
trixie: resolved (fixed in 1.0-268-gdce51f9-1)
VulDB
Booth Authfile Directive improper authentication (EUVD-2022-34807 / Nessus ID 276203)
vuldb·2026-05-26·CVSS 6.5
CVE-2022-2553 [MEDIUM] Booth Authfile Directive improper authentication (EUVD-2022-34807 / Nessus ID 276203)
A vulnerability classified as critical was found in Booth. Affected by this vulnerability is an unknown functionality of the component Authfile Directive. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2022-2553. The attack is only possible within the local network. No exploit exists.
A patch should be applied to remediate this issue.
GHSA
GHSA-9ppf-2r5r-2chh: The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node
ghsa_unreviewed·2022-07-29
CVE-2022-2553 [MEDIUM] CWE-287 GHSA-9ppf-2r5r-2chh: The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
OSV
CVE-2022-2553: The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node
osv·2022-07-28·CVSS 6.5
CVE-2022-2553 [MEDIUM] CVE-2022-2553: The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ClusterLabs/booth/commit/35bf0b7b048d715f671eb68974fb6b4af6528c67https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4T4TTXAABVUCMPUL7XQ2PH5EYYOOQZY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHDOFX7NQFH3UGZZA3SGW5SVMDDHIUVD/https://www.debian.org/security/2022/dsa-5194https://github.com/ClusterLabs/booth/commit/35bf0b7b048d715f671eb68974fb6b4af6528c67https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4T4TTXAABVUCMPUL7XQ2PH5EYYOOQZY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHDOFX7NQFH3UGZZA3SGW5SVMDDHIUVD/https://www.debian.org/security/2022/dsa-5194
2022-07-28
Published