CVE-2022-24755
Bareos vulnerability analysis and mitigation

Overview

CVE-2022-24755 affects Bareos Director versions 18.2 and later but prior to 21.1.0, 20.0.6, and 19.2.12. The vulnerability exists when Bareos Director is built and configured for PAM authentication, where it completely skips authorization checks. Bareos is an open-source software for backup, archiving, and recovery of data for operating systems (NVD, GitHub Advisory).

Technical details

The vulnerability stems from an implementation flaw in the PAM authentication mechanism where the software only performs authentication (username and password matching) but fails to implement proper authorization checks. This means the system does not verify account status, such as checking for expired or disabled accounts. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 CRITICAL by NVD and 8.1 HIGH by GitHub, with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

When exploited, this vulnerability allows users with expired accounts or expired passwords to successfully log into the system. This affects all installations that have PAM authentication enabled, potentially compromising the security of the backup system by allowing unauthorized access (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Bareos Director versions 21.1.0, 20.0.6, and 19.2.12. Users are strongly advised to upgrade to these patched versions immediately. As a temporary workaround, administrators can configure their PAM setup to ensure authentication fails if the user is not authorized, though this may not be possible in all scenarios (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Bareos vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-24755CRITICAL9.8
  • BareosBareos
  • bareos
NoYesMar 15, 2022
CVE-2024-45044HIGH8.8
  • BareosBareos
  • cpe:2.3:a:bareos:bareos
NoYesSep 10, 2024
CVE-2022-24756HIGH7.5
  • BareosBareos
  • bareos
NoYesMar 15, 2022
CVE-2020-11061HIGH7.4
  • BareosBareos
  • bacula
NoYesJul 10, 2020
CVE-2020-4042MEDIUM6.8
  • BareosBareos
  • bareos
NoYesJul 10, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management