Bareos is an open-source backup and recovery platform whose vulnerability footprint concentrates in its core backup software and reflects a mix of authentication and memory-management weaknesses, including capture-replay authentication bypasses, heap-based buffer overflows, improper initialization, and authorization flaws. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bareos over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24755CRITICAL Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is b | Mar 15, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24756HIGH Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and | Mar 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2017-14610HIGH bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to | Sep 20, 2017 | 7.8 | 24 | NO | NO |
CVE-2020-11061HIGH In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest string | Jul 10, 2020 | 7.4 | 21 | NO | NO |
CVE-2020-4042MEDIUM Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated c | Jul 10, 2020 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bareos.
Media articles that mention a CVE ID that affects a product developed by Bareos — matched by CVE ID, not by vendor name.