PT-2022-7148 · Openstack+1 · Openstack+2
Keane Okelley
·
Published
2022-12-21
·
Updated
2023-07-21
·
CVE-2022-38065
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenStack versions prior to git master 05194e7618
Description
A privilege escalation issue exists in the oslo.privsep functionality of OpenStack. This is due to overly permissive functionality within tools that leverage this library within a container, which can lead to increased privileges. The issue is related to insecure privilege management.
Recommendations
For versions prior to git master 05194e7618, consider restricting access to the oslo.privsep functionality to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and adjust the permissions and access controls within containers that utilize the oslo.privsep library to prevent unauthorized privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Openstack
Oslo.Privsep