CVE-2024-45044
- EPSS 0.23%
- Veröffentlicht 10.09.2024 15:15:18
- Zuletzt bearbeitet 10.09.2024 15:50:47
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. "w" for "whoami") the ACL check did not apply to th...
CVE-2022-24755
- EPSS 0.36%
- Veröffentlicht 15.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:01
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization...
CVE-2022-24756
- EPSS 0.53%
- Veröffentlicht 15.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:01
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, a failed PAM authentication will l...
CVE-2020-11061
- EPSS 0.91%
- Veröffentlicht 10.07.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:42
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mi...
CVE-2020-4042
- EPSS 0.27%
- Veröffentlicht 10.07.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:12
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can ...
CVE-2017-14610
- EPSS 0.04%
- Veröffentlicht 20.09.2017 18:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root accoun...