Vulnerabilities
Vulnerable Software
Clusterlabs:  >> Booth  >> 0.1.0  Security Vulnerabilities
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
CVSS Score
5.9
EPSS Score
0.004
Published
2024-06-06
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
CVSS Score
6.5
EPSS Score
0.002
Published
2022-07-28


Contact Us

Shodan ® - All rights reserved