CVE Vulnerabilities

CVE-2022-38060

Improper Privilege Management

Published: Dec 21, 2022 | Modified: May 07, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
KollaOpenstack- (including)- (including)
Red Hat OpenStack Platform 17.1 for RHEL 8RedHatopenstack-tripleo-common-0:15.4.1-17.1.20230927003755.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatopenstack-tripleo-common-0:15.4.1-17.1.20230927010819.el9ost*

Potential Mitigations

References