Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-9543

Опубликовано: 10 мар. 2020
Источник: redhat
CVSS3: 8.3

Описание

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

An access flaw was found in openstack-manila, where the API did not validate the user/project on commands. A malicious user having the UUID of a share-network could view, update, delete, or share resources that did not belong to them. Attackers could also create resources on shared networks (for example, shared file systems or groups of shares).

Меры по смягчению последствий

There is no known mitigation for this issue, the flaw can only be resolved by applying updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)openstack-manilaWill not fix
Red Hat OpenStack Platform 13.0 (Queens)openstack-manilaFixedRHSA-2020:272924.06.2020
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSopenstack-manilaFixedRHSA-2020:272924.06.2020
Red Hat OpenStack Platform 15.0 (Stein)openstack-manilaFixedRHSA-2020:132606.04.2020
Red Hat OpenStack Platform 16.0 (Train)openstack-manilaFixedRHSA-2020:216514.05.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1809855openstack-manila: User with share-network UUID is able to show, create and delete shares

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
почти 6 лет назад

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

CVSS3: 8.3
nvd
почти 6 лет назад

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

CVSS3: 8.3
debian
почти 6 лет назад

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows att ...

CVSS3: 8.3
github
больше 3 лет назад

OpenStack Manila Unprivileged users can retrieve, use and manipulate share networks

CVSS3: 9.4
fstec
почти 6 лет назад

Уязвимость программного средства для общего доступа к файлам openstack-manila, связанная с ошибками использования стандартных разрешений, позволяющая нарушителю получить несанкционированный доступ к общим файлам

8.3 High

CVSS3