CVE Vulnerabilities

CVE-2022-41835

Improper Privilege Management

Published: Oct 19, 2022 | Modified: Oct 24, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
F5os-a F5 1.0.0 (including) 1.1.0 (excluding)
F5os-c F5 1.3.0 (excluding) 1.5.0 (excluding)

Potential Mitigations

References