CVE-2024-45044

HIGH

bareos 21.1.11 22.0.0-22.1.6 23.0.0-23.0.4 - Improper Authorization via Command Abbreviation Bypass

Title source: llm
STIX 2.1

Description

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. "w" for "whoami") the ACL check did not apply to the full form (i.e. "whoami") but to the abbreviated form (i.e. "w"). If the command ACL is configured with negative ACL that should forbid using the "whoami" command, you could still use "w" or "who" as a command successfully. Fixes for the problem are shipped in Bareos versions 23.0.4, 22.1.6 and 21.1.11. If only positive command ACLs are used without any negation, the problem does not occur.

Scores

CVSS v3 8.8
EPSS 0.0053
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (3)
bareos/bareos < 21.1.11
bareos/bareos >= 22.0.0, < 22.1.6
bareos/bareos >= 23.0.0, < 23.0.4
Published Sep 10, 2024
Tracked Since Feb 18, 2026