PT-2022-24179 · Openstack · Openstack Kolla

Brian Scott

+1

·

Published

2022-12-21

·

Updated

2023-07-21

·

CVE-2022-38060

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenStack Kolla git master 05194e7618
Description A privilege escalation issue exists in the sudo functionality. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
Recommendations For OpenStack Kolla git master 05194e7618, ensure proper configuration of /etc/sudoers within containers to prevent privilege escalation. As a temporary workaround, consider restricting access to the sudo functionality until a proper configuration can be implemented.

Fix

Improper Privilege Management

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2022-38060
GHSA-RVXR-PF5F-J2QJ
RHSA-2024:0191
RHSA-2024:0216

Affected Products

Openstack Kolla