PT-2022-7148 · Openstack+1 · Openstack+2

Keane Okelley

·

Published

2022-12-21

·

Updated

2023-07-21

·

CVE-2022-38065

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenStack versions prior to git master 05194e7618
Description A privilege escalation issue exists in the oslo.privsep functionality of OpenStack. This is due to overly permissive functionality within tools that leverage this library within a container, which can lead to increased privileges. The issue is related to insecure privilege management.
Recommendations For versions prior to git master 05194e7618, consider restricting access to the oslo.privsep functionality to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and adjust the permissions and access controls within containers that utilize the oslo.privsep library to prevent unauthorized privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2023-07866
CVE-2022-38065

Affected Products

Debian
Openstack
Oslo.Privsep