Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-9543

Опубликовано: 12 мар. 2020
Источник: debian

Описание

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
manilafixed1:9.0.0-5package
manilafixed1:7.0.0-1+deb10u1busterpackage
manilano-dsastretchpackage

Примечания

  • https://bugs.launchpad.net/manila/+bug/1861485

  • https://security.openstack.org/ossa/OSSA-2020-002.html

Связанные уязвимости

CVSS3: 8.3
ubuntu
почти 6 лет назад

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

CVSS3: 8.3
redhat
почти 6 лет назад

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

CVSS3: 8.3
nvd
почти 6 лет назад

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

CVSS3: 8.3
github
больше 3 лет назад

OpenStack Manila Unprivileged users can retrieve, use and manipulate share networks

CVSS3: 9.4
fstec
почти 6 лет назад

Уязвимость программного средства для общего доступа к файлам openstack-manila, связанная с ошибками использования стандартных разрешений, позволяющая нарушителю получить несанкционированный доступ к общим файлам