{"id":"CVE-2022-2553","details":"The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.","modified":"2026-08-12T13:00:06.962926Z","published":"2022-07-28T00:00:00Z","related":["ALSA-2022:6439","ALSA-2022:6580","SUSE-SU-2022:2605-1","SUSE-SU-2022:2606-1","SUSE-SU-2022:2607-1","SUSE-SU-2022:2608-1","SUSE-SU-2022:2609-1","openSUSE-SU-2024:12315-1"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2553.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Booth versions after v1.0-85-gda79b8b are vulnerable. Resolved in booth v1.0-263-g35bf0b7."},{"last_affected":"Booth versions after v1.0-85-gda79b8b are vulnerable. Resolved in booth v1.0-263-g35bf0b7."}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2553.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4T4TTXAABVUCMPUL7XQ2PH5EYYOOQZY/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHDOFX7NQFH3UGZZA3SGW5SVMDDHIUVD/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2553"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5194"},{"type":"FIX","url":"https://github.com/ClusterLabs/booth/commit/35bf0b7b048d715f671eb68974fb6b4af6528c67"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/clusterlabs/booth","events":[{"introduced":"0"},{"fixed":"35bf0b7b048d715f671eb68974fb6b4af6528c67"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:clusterlabs:booth:*:*:*:*:*:*:*:*"}}],"versions":["v1.0","v1.0rc1","v0.2.0","v0.1.7","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.2","v0.1.0"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/clusterlabs/booth/commit/35bf0b7b048d715f671eb68974fb6b4af6528c67","target":{"file":"src/main.c","function":"setup_config"},"deprecated":false,"digest":{"function_hash":"149510054174933947535674704961299673793","length":901},"id":"CVE-2022-2553-352f9de4","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/clusterlabs/booth/commit/35bf0b7b048d715f671eb68974fb6b4af6528c67","target":{"file":"src/main.c"},"deprecated":false,"digest":{"line_hashes":["335119658293112424394991090198767395100","65978872216503566394160499784130448295","21845935033621291117597346218735165249","134854276876856949574566516929111687573"],"threshold":0.9},"id":"CVE-2022-2553-878d7758","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2553.json","vanir_signatures_modified":"2026-08-12T13:00:06Z"}}],"schema_version":"1.9.0"}