CVE-2022-1049
pcs: improper authentication via PAM
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.
Se encontró un fallo en la herramienta de configuración de Pacemaker (pcs). El demonio pcs permitía que las cuentas caducadas y las cuentas con contraseñas caducadas iniciaran sesión cuando era usada la autenticación PAM. Por lo tanto, las cuentas caducadas no privilegiadas a las que les había denegado el acceso podían seguir iniciando sesión
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon allowed expired accounts and accounts with expired passwords to log in when using PAM authentication. Unprivileged, expired accounts with previously denied access could still log in.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-22 CVE Reserved
- 2022-03-25 CVE Published
- 2024-06-16 EPSS Updated
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2022/09/msg00017.html | Mailing List |
URL | Date | SRC |
---|---|---|
https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2022/dsa-5226 | 2023-12-14 | |
https://access.redhat.com/security/cve/CVE-2022-1049 | 2022-11-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2066629 | 2022-11-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Clusterlabs Search vendor "Clusterlabs" | Pcs Search vendor "Clusterlabs" for product "Pcs" | <= 0.11.2 Search vendor "Clusterlabs" for product "Pcs" and version " <= 0.11.2" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|