Lucene search

K
cve[email protected]CVE-2024-3049
HistoryJun 06, 2024 - 6:15 a.m.

CVE-2024-3049

2024-06-0606:15:09
CWE-345
web.nvd.nist.gov
30
booth
cluster ticket manager
invalid hmac
flaw
cve-2024-3049

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.2%

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

Affected configurations

NVD
Node
clusterlabsboothRange<1.1
Node
redhatenterprise_linuxMatch7.0
OR
redhatenterprise_linuxMatch8.0
OR
redhatenterprise_linuxMatch9.0
OR
redhatenterprise_linux_eusMatch8.4
OR
redhatenterprise_linux_eusMatch8.8
OR
redhatenterprise_linux_eusMatch9.2
OR
redhatenterprise_linux_for_arm_64Match8.0_aarch64
OR
redhatenterprise_linux_for_arm_64Match8.8_aarch64
OR
redhatenterprise_linux_for_arm_64Match9.2_aarch64
OR
redhatenterprise_linux_for_arm_64Match9.4_aarch64
OR
redhatenterprise_linux_for_ibm_z_systemsMatch8.0_s390x
OR
redhatenterprise_linux_for_ibm_z_systemsMatch9.2_s390x
OR
redhatenterprise_linux_for_ibm_z_systemsMatch9.4_s390x
OR
redhatenterprise_linux_for_ibm_z_systems_eusMatch8.8_s390x
OR
redhatenterprise_linux_for_power_little_endian_eusMatch8.0_ppc64le
OR
redhatenterprise_linux_for_power_little_endian_eusMatch8.4_ppc64le
OR
redhatenterprise_linux_for_power_little_endian_eusMatch8.8_ppc64le
OR
redhatenterprise_linux_for_power_little_endian_eusMatch9.2_ppc64le
OR
redhatenterprise_linux_for_power_little_endian_eusMatch9.4_ppc64le
OR
redhatenterprise_linux_server_update_services_for_sap_solutionsMatch8.4

CNA Affected

[
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 8",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "booth",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:1.1-1.el8_10.1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:enterprise_linux:8::highavailability",
      "cpe:/a:redhat:enterprise_linux:8::resilientstorage"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "booth",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:1.0-199.1.ac1d34c.git.el8_4.2",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhel_e4s:8.4::highavailability",
      "cpe:/a:redhat:rhel_tus:8.4::highavailability"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "booth",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:1.0-199.1.ac1d34c.git.el8_4.2",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhel_e4s:8.4::highavailability",
      "cpe:/a:redhat:rhel_tus:8.4::highavailability"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 8.8 Extended Update Support",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "booth",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:1.0-283.1.9d4029a.git.el8_8.1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhel_eus:8.8::highavailability",
      "cpe:/a:redhat:rhel_eus:8.8::resilientstorage"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 9",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "booth",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:1.1-1.el9_4.1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:enterprise_linux:9::highavailability",
      "cpe:/a:redhat:enterprise_linux:9::resilientstorage"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 9.2 Extended Update Support",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "booth",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:1.0-283.1.9d4029a.git.el9_2.1",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:rhel_eus:9.2::resilientstorage",
      "cpe:/a:redhat:rhel_eus:9.2::highavailability"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 7",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "booth",
    "defaultStatus": "affected",
    "cpes": [
      "cpe:/o:redhat:enterprise_linux:7"
    ]
  }
]

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.2%