CVE Vulnerabilities

CVE-2022-29526

Improper Privilege Management

Published: Jun 23, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
6.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Go Golang * 1.17.10 (excluding)
Go Golang 1.18.0 (including) 1.18.2 (excluding)
OpenShift Service Mesh 2.1 RedHat servicemesh-operator-0:2.1.5-1.el8 *
OpenShift Service Mesh 2.1 RedHat servicemesh-prometheus-0:2.23.0-9.el8 *
OSSO-1.0-RHEL-8 RedHat openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8:v1.0-28 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 RedHat rhacm2/thanos-rhel7:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/agent-service-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/assisted-installer-agent-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/cert-policy-controller-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/cluster-curator-controller-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/clusterlifecycle-state-metrics-rhel8:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/governance-policy-propagator-rhel8:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/governance-policy-spec-sync-rhel8:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/iam-policy-controller-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/insights-client-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/klusterlet-addon-controller-rhel8:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/multicloud-manager-rhel8:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/multiclusterhub-repo-rhel8:v2.3.11-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/multiclusterhub-rhel8:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/multicluster-operators-application-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/multicluster-operators-channel-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/multicluster-operators-placementrule-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/observatorium-rhel8-operator:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/prometheus-alertmanager-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/registration-rhel8:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/registration-rhel8-operator:v2.3.11-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/search-collector-rhel8:v2.3.11-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/search-rhel8:v2.3.11-5 *
Red Hat Ceph Storage 6.1 RedHat rhceph/rhceph-6-dashboard-rhel9:6-75 *
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8060020220527144311.97d7f71f *
Red Hat Enterprise Linux 9 RedHat golang-0:1.17.12-1.el9_0 *
Red Hat Enterprise Linux 9 RedHat go-toolset-0:1.17.12-1.el9_0 *
Red Hat Migration Toolkit for Containers 1.7 RedHat rhmtc/openshift-migration-must-gather-rhel8:v1.7.3-4 *
Red Hat OpenShift Container Platform 4.10 RedHat atomic-openshift-service-idler-0:4.10.0-202207192015.p0.g39cfc66.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.10 RedHat cri-o-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el7 *
Red Hat OpenShift Container Platform 4.10 RedHat openshift-0:4.10.0-202207192015.p0.g012e945.assembly.stream.el7 *
Red Hat OpenShift Container Platform 4.10 RedHat openshift-clients-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el7 *
Red Hat OpenShift Data Foundation 4.11 on RHEL8 RedHat odf4/odf-csi-addons-sidecar-rhel8:v4.11.0-23 *
Red Hat OpenShift Data Foundation 4.11 on RHEL8 RedHat odf4/odf-topolvm-rhel8:v4.11.0-24 *
Red Hat OpenShift Data Foundation 4.11 on RHEL8 RedHat odf4/rook-ceph-rhel8-operator:v4.11.0-49 *
RHACS-3.72-RHEL-8 RedHat advanced-cluster-security/rhacs-docs-rhel8:3.72.0-3 *
RHACS-3.72-RHEL-8 RedHat advanced-cluster-security/rhacs-main-rhel8:3.72.0-3 *
RHACS-3.72-RHEL-8 RedHat advanced-cluster-security/rhacs-rhel8-operator:3.72.0-3 *
RHACS-3.72-RHEL-8 RedHat advanced-cluster-security/rhacs-roxctl-rhel8:3.72.0-4 *
RHACS-3.72-RHEL-8 RedHat advanced-cluster-security/rhacs-scanner-rhel8:3.72.0-3 *
RHACS-3.72-RHEL-8 RedHat advanced-cluster-security/rhacs-scanner-slim-rhel8:3.72.0-3 *
RHEL-8-CNV-4.12 RedHat container-native-virtualization/libguestfs-tools:v4.12.0-255 *
STF-1.5-RHEL-8 RedHat stf/sg-core-rhel8:5.1.1-2 *
Golang Ubuntu trusty *
Golang-1.10 Ubuntu bionic *
Golang-1.10 Ubuntu trusty *
Golang-1.10 Ubuntu trusty/esm *
Golang-1.10 Ubuntu xenial *
Golang-1.13 Ubuntu bionic *
Golang-1.13 Ubuntu impish *
Golang-1.13 Ubuntu kinetic *
Golang-1.13 Ubuntu xenial *
Golang-1.14 Ubuntu focal *
Golang-1.15 Ubuntu impish *
Golang-1.16 Ubuntu bionic *
Golang-1.16 Ubuntu esm-apps/bionic *
Golang-1.16 Ubuntu esm-apps/focal *
Golang-1.16 Ubuntu focal *
Golang-1.16 Ubuntu impish *
Golang-1.16 Ubuntu trusty *
Golang-1.16 Ubuntu xenial *
Golang-1.17 Ubuntu impish *
Golang-1.17 Ubuntu trusty *
Golang-1.17 Ubuntu xenial *
Golang-1.18 Ubuntu bionic *
Golang-1.18 Ubuntu esm-apps/bionic *
Golang-1.18 Ubuntu esm-apps/focal *
Golang-1.18 Ubuntu esm-apps/xenial *
Golang-1.18 Ubuntu focal *
Golang-1.18 Ubuntu jammy *
Golang-1.18 Ubuntu trusty *
Golang-1.18 Ubuntu xenial *
Golang-1.6 Ubuntu trusty *
Golang-1.6 Ubuntu xenial *
Golang-1.8 Ubuntu bionic *
Golang-1.9 Ubuntu bionic *

Potential Mitigations

References