CVE-2022-24756
Bareos vulnerability analysis and mitigation

Overview

CVE-2022-24756 affects Bareos, an open source software for backup, archiving, and recovery of data for operating systems. The vulnerability was discovered in Bareos Director versions >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 when built and configured for PAM authentication. The issue was disclosed on March 15, 2022 (NVD).

Technical details

The vulnerability is a memory leak that occurs during failed PAM authentication attempts. When PAM authentication fails, a small amount of memory is leaked and not properly released. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The weakness has been categorized as CWE-401: Missing Release of Memory after Effective Lifetime (GitHub Advisory).

Impact

An attacker who can access the PAM Console (either by knowing the shared secret or via the WebUI) can exploit this vulnerability by flooding the Director with failing login attempts. This can eventually lead to an out-of-memory condition, rendering the Director inoperable and causing a denial of service (GitHub Advisory).

Exploitability

The vulnerability requires network access and the ability to interact with the PAM Console, either through knowledge of the shared secret or access to the WebUI. No special privileges or user interaction are required beyond this initial access requirement (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Bareos Director versions 21.1.0, 20.0.6, and 19.2.12. Users are strongly advised to upgrade to one of these patched versions. For users unable to upgrade immediately, a workaround is available by disabling PAM authentication entirely. It should be noted that the upgrade may break currently working PAM configurations, and users should review their PAM configuration after upgrading (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Bareos vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-24755CRITICAL9.8
  • Bareos logoBareos
  • cpe:2.3:a:bareos:bareos
NoYesMar 15, 2022
CVE-2024-45044HIGH8.8
  • Bareos logoBareos
  • bareos
NoYesSep 10, 2024
CVE-2022-24756HIGH7.5
  • Bareos logoBareos
  • bareos
NoYesMar 15, 2022
CVE-2020-11061HIGH7.4
  • Bareos logoBareos
  • cpe:2.3:a:bareos:bareos
NoYesJul 10, 2020
CVE-2020-4042MEDIUM6.8
  • Bareos logoBareos
  • cpe:2.3:a:bareos:bareos
NoYesJul 10, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management