Bug 2109251 (CVE-2022-2553)

Summary: CVE-2022-2553 booth: authfile directive in booth config file is completely ignored.
Product: [Other] Security Response Reporter: Todd Cullum <tcullum>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: cfeist, cluster-maint, jfriesse
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: booth v1.0-263-g35bf0b7 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in booth in the way it handles the authfile directive in configuration files, which causes authentication to be skipped between nodes. As a result, an attacker-controlled node that does not have the correct authentication key does not prevent communication with other nodes in the cluster.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-08-09 12:54:21 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2111667, 2111668, 2111669, 2113967, 2113968, 2113970    
Bug Blocks: 2108702    

Description Todd Cullum 2022-07-20 18:48:39 UTC
The authfile directive in booth config file is completely ignored, breaking authentication from server to server.

References:
https://github.com/ClusterLabs/booth/issues/114
https://github.com/ClusterLabs/booth/pull/115

Comment 3 Zack Miele 2022-07-27 19:06:53 UTC
Created booth tracking bugs for this issue:

Affects: fedora-all [bug 2111667]

Comment 6 errata-xmlrpc 2022-08-30 21:45:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:6250 https://access.redhat.com/errata/RHSA-2022:6250

Comment 7 errata-xmlrpc 2022-09-13 09:40:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:6439 https://access.redhat.com/errata/RHSA-2022:6439

Comment 8 errata-xmlrpc 2022-09-20 13:33:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2022:6580 https://access.redhat.com/errata/RHSA-2022:6580