CVE-2022-1049

Source
https://cve.org/CVERecord?id=CVE-2022-1049
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-1049.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-1049
Downstream
Related
Published
2022-03-25T18:03:01Z
Modified
2026-05-15T11:54:36.855695900Z
Summary
[none]
Details

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.

Database specific
{
    "cwe_ids": [
        "CWE-287"
    ],
    "cna_assigner": "redhat",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "last_affected": "pcs versions <= v0.11.2"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1049.json"
}
References

Affected packages