CVE Vulnerabilities

CVE-2022-29526

Improper Privilege Management

Published: Jun 23, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
6.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.17.10 (excluding)
GoGolang1.18.0 (including)1.18.2 (excluding)
OpenShift Service Mesh 2.1RedHatservicemesh-operator-0:2.1.5-1.el8*
OpenShift Service Mesh 2.1RedHatservicemesh-prometheus-0:2.23.0-9.el8*
OSSO-1.0-RHEL-8RedHatopenshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8:v1.0-28*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7RedHatrhacm2/thanos-rhel7:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/agent-service-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/assisted-installer-agent-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/cert-policy-controller-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/cluster-curator-controller-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/clusterlifecycle-state-metrics-rhel8:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/governance-policy-propagator-rhel8:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/governance-policy-spec-sync-rhel8:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/iam-policy-controller-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/insights-client-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/klusterlet-addon-controller-rhel8:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/multicloud-manager-rhel8:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/multiclusterhub-repo-rhel8:v2.3.11-7*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/multiclusterhub-rhel8:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/multicluster-operators-application-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/multicluster-operators-channel-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/multicluster-operators-placementrule-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/observatorium-rhel8-operator:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/prometheus-alertmanager-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/registration-rhel8:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/registration-rhel8-operator:v2.3.11-6*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/search-collector-rhel8:v2.3.11-5*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/search-rhel8:v2.3.11-5*
Red Hat Ceph Storage 6.1RedHatrhceph/rhceph-6-dashboard-rhel9:6-75*
Red Hat Enterprise Linux 8RedHatgo-toolset:rhel8-8060020220527144311.97d7f71f*
Red Hat Enterprise Linux 9RedHatgolang-0:1.17.12-1.el9_0*
Red Hat Enterprise Linux 9RedHatgo-toolset-0:1.17.12-1.el9_0*
Red Hat Migration Toolkit for Containers 1.7RedHatrhmtc/openshift-migration-must-gather-rhel8:v1.7.3-4*
Red Hat OpenShift Container Platform 4.10RedHatatomic-openshift-service-idler-0:4.10.0-202207192015.p0.g39cfc66.assembly.stream.el8*
Red Hat OpenShift Container Platform 4.10RedHatcri-o-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el8*
Red Hat OpenShift Container Platform 4.10RedHatopenshift-0:4.10.0-202207192015.p0.g012e945.assembly.stream.el8*
Red Hat OpenShift Container Platform 4.10RedHatopenshift-clients-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el8*
Red Hat OpenShift Data Foundation 4.11 on RHEL8RedHatodf4/odf-csi-addons-sidecar-rhel8:v4.11.0-23*
Red Hat OpenShift Data Foundation 4.11 on RHEL8RedHatodf4/odf-topolvm-rhel8:v4.11.0-24*
Red Hat OpenShift Data Foundation 4.11 on RHEL8RedHatodf4/rook-ceph-rhel8-operator:v4.11.0-49*
RHACS-3.72-RHEL-8RedHatadvanced-cluster-security/rhacs-docs-rhel8:3.72.0-3*
RHACS-3.72-RHEL-8RedHatadvanced-cluster-security/rhacs-main-rhel8:3.72.0-3*
RHACS-3.72-RHEL-8RedHatadvanced-cluster-security/rhacs-rhel8-operator:3.72.0-3*
RHACS-3.72-RHEL-8RedHatadvanced-cluster-security/rhacs-roxctl-rhel8:3.72.0-4*
RHACS-3.72-RHEL-8RedHatadvanced-cluster-security/rhacs-scanner-rhel8:3.72.0-3*
RHACS-3.72-RHEL-8RedHatadvanced-cluster-security/rhacs-scanner-slim-rhel8:3.72.0-3*
RHEL-8-CNV-4.12RedHatcontainer-native-virtualization/libguestfs-tools:v4.12.0-255*
STF-1.5-RHEL-8RedHatstf/sg-core-rhel8:5.1.1-2*
GolangUbuntutrusty*
Golang-1.10Ubuntubionic*
Golang-1.10Ubuntutrusty*
Golang-1.10Ubuntutrusty/esm*
Golang-1.10Ubuntuxenial*
Golang-1.13Ubuntubionic*
Golang-1.13Ubuntuimpish*
Golang-1.13Ubuntukinetic*
Golang-1.13Ubuntuxenial*
Golang-1.14Ubuntufocal*
Golang-1.15Ubuntuimpish*
Golang-1.16Ubuntubionic*
Golang-1.16Ubuntuesm-apps/bionic*
Golang-1.16Ubuntuesm-apps/focal*
Golang-1.16Ubuntufocal*
Golang-1.16Ubuntuimpish*
Golang-1.16Ubuntutrusty*
Golang-1.16Ubuntuxenial*
Golang-1.17Ubuntuimpish*
Golang-1.17Ubuntutrusty*
Golang-1.17Ubuntuxenial*
Golang-1.18Ubuntubionic*
Golang-1.18Ubuntuesm-apps/bionic*
Golang-1.18Ubuntuesm-apps/focal*
Golang-1.18Ubuntuesm-apps/xenial*
Golang-1.18Ubuntufocal*
Golang-1.18Ubuntujammy*
Golang-1.18Ubuntutrusty*
Golang-1.18Ubuntuxenial*
Golang-1.6Ubuntutrusty*
Golang-1.6Ubuntuxenial*
Golang-1.8Ubuntubionic*
Golang-1.9Ubuntubionic*

Potential Mitigations

References