AZL-25645

    Dashboard / Vulnerabilities / AZL-25645

    AZL-25645

    Published: 28 Jul 2022Last Modified: 21 Apr 2026
    Upstream:

    Summary: CVE-2022-2553 affecting package booth for versions less than 1.0-8

    Details: The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

    Affected packages

    Package

    Name: booth

    Purl: pkg:rpm/azure-linux/booth

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0-8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    AZL-25645 | CVE-DB