CVE Vulnerabilities

CVE-2022-38060

Improper Privilege Management

Published: Dec 21, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Kolla Openstack - (including) - (including)
Red Hat OpenStack Platform 17.1 for RHEL 8 RedHat openstack-tripleo-common-0:15.4.1-17.1.20230927003755.el8ost *
Red Hat OpenStack Platform 17.1 for RHEL 9 RedHat openstack-tripleo-common-0:15.4.1-17.1.20230927010819.el9ost *

Potential Mitigations

References