CVE-2022-1049

high

Description

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.

References

https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5

https://lists.debian.org/debian-lts-announce/2022/09/msg00017.html

https://www.debian.org/security/2022/dsa-5226

Details

Source: Mitre, NVD

Published: 2022-03-25

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High