Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, a failed PAM authentication will leak a small amount of memory. An attacker that is able to use the PAM Console (i.e. by knowing the shared secret or via the WebUI) can flood the Director with failing login attempts which will eventually lead to an out-of-memory condition in which the Director will not work anymore. Bareos Director versions 21.1.0, 20.0.6 and 19.2.12 contain a Bugfix for this problem. Users who are unable to upgrade may disable PAM authentication as a workaround.
Conclusion & alert: CVE-2022-24756 is rated High Exploit Risk (71/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.80%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-22 | 0.53% | 0.80% | +0.27% |
| 2 | 2025-11-21 | 0.80% | 0.53% | -0.27% |
| 3 | 2025-11-18 | — | 0.80% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2022-24756: 1 source package rows (bareos); 2 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 2. | https://security.alpinelinux.org/vuln/CVE-2022-24756 |
ubuntu
|
low | CVE-2022-24756 low priority: Ubuntu including 1 source packages (bareos), 3 status rows across 3 suites (trusty, upstream, xenial): ignored 1, needed 1, needs-triage 1. | https://ubuntu.com/security/CVE-2022-24756 |
| URL | Tags |
|---|---|
| https://github.com/bareos/bareos/pull/1115 | Patch Third Party Advisory |
| https://github.com/bareos/bareos/pull/1119 | Patch Third Party Advisory |
| https://github.com/bareos/bareos/pull/1121 | Patch Third Party Advisory |
| https://github.com/bareos/bareos/security/advisories/GHSA-jh55-4wgw-xc9j | Third Party Advisory |
| https://huntr.dev/bounties/480121f2-bc3c-427e-986e-5acffb1606c5/ | Exploit Patch Third Party Advisory |