PT-2020-2668 · Openstack · Openstack Manila

Tobias Rydberg

·

Published

2020-03-10

·

Updated

2022-05-24

·

CVE-2020-9543

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Manila versions prior to 7.4.1 OpenStack Manila versions 8.0.0 through 8.1.0 OpenStack Manila versions 9.0.0 through 9.1.0
Description The issue allows attackers to view, update, delete, or share resources that do not belong to them due to a context-free lookup of a UUID. This can also enable the creation of resources, such as shared file systems and groups of shares on such share networks. The vulnerability is related to errors in using standard permissions, which can allow a remote attacker to gain unauthorized access to shared files if the UUID value is known.
Recommendations For versions prior to 7.4.1, update to version 7.4.1 or later. For versions 8.0.0 through 8.1.0, update to version 8.1.1 or later. For versions 9.0.0 through 9.1.0, update to version 9.1.1 or later.

Exploit

Fix

Improper Access Control

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02718
CVE-2020-9543
GHSA-JX7V-GMQC-6XRJ
PYSEC-2020-63
RHSA-2020:1326
RHSA-2020:2165
RHSA-2020:2729
SUSE-SU-2020:0659-1
SUSE-SU-2020:0660-1
SUSE-SU-2020:1066-1
SUSE-SU-2020:1190-1

Affected Products

Openstack Manila