CVE-2024-3049
published 2024-06-06CVE-2024-3049: A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.53%
41.9th percentile
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clusterlabs | booth | < 1.1 | 1.1 |
| clusterlabs | booth | >= 0 < 1.0-237-gdd88847-2+deb11u2 | 1.0-237-gdd88847-2+deb11u2 |
| clusterlabs | booth | >= 0 < 1.0-283-g9d4029a-2+deb12u1 | 1.0-283-g9d4029a-2+deb12u1 |
| clusterlabs | booth | >= 0 < 1.1-2 | 1.1-2 |
| clusterlabs | booth | >= 0 < 1.1-2 | 1.1-2 |
| debian | booth | < booth 1.0-283-g9d4029a-2+deb12u1 (bookworm) | booth 1.0-283-g9d4029a-2+deb12u1 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-3049: A flaw was found in Booth, a cluster ticket manager
osv·2024-06-06·CVSS 5.9
CVE-2024-3049 [MEDIUM] CVE-2024-3049: A flaw was found in Booth, a cluster ticket manager
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
GHSA
GHSA-gqh6-f673-ccgc: A flaw was found in Booth, a cluster ticket manager
ghsa_unreviewed·2024-06-06
CVE-2024-3049 [HIGH] CWE-345 GHSA-gqh6-f673-ccgc: A flaw was found in Booth, a cluster ticket manager
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
Red Hat
booth: specially crafted hash can lead to invalid HMAC being accepted by Booth server
vendor_redhat·2024-05-27·CVSS 5.9
CVE-2024-3049 [MEDIUM] CWE-345 booth: specially crafted hash can lead to invalid HMAC being accepted by Booth server
booth: specially crafted hash can lead to invalid HMAC being accepted by Booth server
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: booth (Red Hat Enterprise Linux 10) - Out of support scope
Package: booth (Red Hat Ente
Debian
CVE-2024-3049: booth - A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash...
vendor_debian·2024·CVSS 5.9
CVE-2024-3049 [MEDIUM] CVE-2024-3049: booth - A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash...
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
Scope: local
bookworm: resolved (fixed in 1.0-283-g9d4029a-2+deb12u1)
bullseye: resolved (fixed in 1.0-237-gdd88847-2+deb11u2)
forky: resolved (fixed in 1.1-2)
sid: resolved (fixed in 1.1-2)
trixie: resolved (fixed in 1.1-2)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:3657https://access.redhat.com/errata/RHSA-2024:3658https://access.redhat.com/errata/RHSA-2024:3659https://access.redhat.com/errata/RHSA-2024:3660https://access.redhat.com/errata/RHSA-2024:3661https://access.redhat.com/errata/RHSA-2024:4400https://access.redhat.com/errata/RHSA-2024:4411https://access.redhat.com/security/cve/CVE-2024-3049https://bugzilla.redhat.com/show_bug.cgi?id=2272082https://github.com/ClusterLabs/booth/pull/142https://access.redhat.com/errata/RHSA-2024:3657https://access.redhat.com/errata/RHSA-2024:3658https://access.redhat.com/errata/RHSA-2024:3659https://access.redhat.com/errata/RHSA-2024:3660https://access.redhat.com/errata/RHSA-2024:3661https://access.redhat.com/errata/RHSA-2024:4400https://access.redhat.com/errata/RHSA-2024:4411https://access.redhat.com/security/cve/CVE-2024-3049https://bugzilla.redhat.com/show_bug.cgi?id=2272082https://lists.debian.org/debian-lts-announce/2024/09/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ERCFM3HXFJKLEMMWU3CZLPKH5LZAEDAN/https://lists.fedoraproject.org/archives/list/[email protected]/message/KPK5BHYOB7CFFRQAN55YV5LH44PWHMQD/
2024-06-06
Published