Bareos Fixes Command ACL Issue
CVE-2024-45044
What is CVE-2024-45044?
A vulnerability in Bareos backup software allows users to bypass command access control lists (ACLs) when executing abbreviations of commands. Specifically, if a command ACL prohibits certain commands, users can potentially exploit this by using shorter, abbreviated versions of those commands without triggering the ACL checks. This flaw permits the execution of commands intended to be restricted, such as using 'w' as a shorthand for 'whoami'. This behavior poses risks mainly when negative ACLs are active, enabling unintended command execution. The issue has been resolved in Bareos versions 23.0.4, 22.1.6, and 21.1.11, ensuring proper enforcement of command permissions.
Affected Version(s)
bareos >= 23.0.0, < 23.0.4 < 23.0.0, 23.0.4
bareos >= 22.0.0, < 22.1.6 < 22.0.0, 22.1.6
bareos < 21.1.11 < 21.1.11