CVE Vulnerabilities

CVE-2022-38065

Improper Privilege Management

Published: Dec 21, 2022 | Modified: Jul 21, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Openstack Redhat - (including) - (including)
Openstack Ubuntu esm-apps/xenial *
Openstack Ubuntu trusty *
Openstack Ubuntu xenial *
Python-oslo.privsep Ubuntu bionic *
Python-oslo.privsep Ubuntu devel *
Python-oslo.privsep Ubuntu esm-infra/bionic *
Python-oslo.privsep Ubuntu focal *
Python-oslo.privsep Ubuntu jammy *
Python-oslo.privsep Ubuntu kinetic *
Python-oslo.privsep Ubuntu lunar *
Python-oslo.privsep Ubuntu trusty *
Python-oslo.privsep Ubuntu xenial *

Potential Mitigations

References