VulnerabilityModified
CVE-2022-1049
The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication.
HIGH 8.8EPSS 1.95%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- clusterlabs/pcs · debian/debian linux
- Source
- secalert@redhat.com
References
- https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00017.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5226Third Party Advisory
- https://huntr.dev/bounties/7aa921fc-a568-4fd8-96f4-7cd826246aa5Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00017.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5226Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.