A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openstack | Redhat | - (including) | - (including) |
Openstack | Ubuntu | esm-apps/xenial | * |
Openstack | Ubuntu | trusty | * |
Openstack | Ubuntu | xenial | * |
Python-oslo.privsep | Ubuntu | bionic | * |
Python-oslo.privsep | Ubuntu | devel | * |
Python-oslo.privsep | Ubuntu | esm-infra/bionic | * |
Python-oslo.privsep | Ubuntu | focal | * |
Python-oslo.privsep | Ubuntu | jammy | * |
Python-oslo.privsep | Ubuntu | kinetic | * |
Python-oslo.privsep | Ubuntu | lunar | * |
Python-oslo.privsep | Ubuntu | trusty | * |
Python-oslo.privsep | Ubuntu | xenial | * |