Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-38060

Опубликовано: 06 сент. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

Отчет

To exploit this vulnerability, an attacker would need to have specialized access that allows them to modify how the container is run. The attacker would need to either modify the container's definition (such as by configuring environment variables or selecting the container image) or modify files in the container's file system. Both of these actions are typically restricted by user and group permissions. Hence, the impact for OpenStack is reduced to moderate.

Меры по смягчению последствий

/etc/sudoers within the container should use the secure_path option to prevent the PATH environment variable from being modified. However, this will not prevent other possibly dangerous environment variables from being changed. Ideally, the setenv option would be removed from /etc/sudoers altogether, and env_keep could be used for any safe environment variables that do not introduce security holes. To avoid container compromises resulting in host compromise, avoid using privileged containers; prefer adding individual capabilities as needed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.1openstack-tripleo-commonWill not fix
Red Hat OpenStack Platform 16.2openstack-tripleo-commonWill not fix
Red Hat OpenStack Platform 17.0openstack-tripleo-commonOut of support scope
Red Hat OpenStack Platform 18.0python-tcibAffected
Red Hat OpenStack Platform 17.1 for RHEL 8openstack-tripleo-commonFixedRHSA-2024:019116.01.2024
Red Hat OpenStack Platform 17.1 for RHEL 9openstack-tripleo-commonFixedRHSA-2024:021616.01.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2124758openstack/kolla: sudo privilege escalation vulnerability

EPSS

Процентиль: 10%
0.00034
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 3 лет назад

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

CVSS3: 8.8
debian
около 3 лет назад

A privilege escalation vulnerability exists in the sudo functionality ...

CVSS3: 7.8
github
около 3 лет назад

OpenStack Kolla sudo privilege escalation vulnerability

EPSS

Процентиль: 10%
0.00034
Низкий

7.8 High

CVSS3