CVE Vulnerabilities

CVE-2022-38065

Improper Privilege Management

Published: Dec 21, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
OpenstackRedhat- (including)- (including)
OpenstackUbuntuesm-apps/xenial*
OpenstackUbuntutrusty*
OpenstackUbuntuxenial*
Python-oslo.privsepUbuntubionic*
Python-oslo.privsepUbuntudevel*
Python-oslo.privsepUbuntuesm-infra/bionic*
Python-oslo.privsepUbuntuesm-infra/focal*
Python-oslo.privsepUbuntufocal*
Python-oslo.privsepUbuntujammy*
Python-oslo.privsepUbuntukinetic*
Python-oslo.privsepUbuntulunar*
Python-oslo.privsepUbuntutrusty*
Python-oslo.privsepUbuntuxenial*

Potential Mitigations

References