Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-38065

Опубликовано: 10 окт. 2022
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

A privilege escalation flaw was found in the oslo-privsep functionality in OpenStack. Overly permissive functionality in the tools leveraging this library within a container can lead to increased privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)python-oslo-privsepNot affected
Red Hat OpenStack Platform 16.1python-oslo-privsepNot affected
Red Hat OpenStack Platform 16.2python-oslo-privsepNot affected
Red Hat OpenStack Platform 17.0python-oslo-privsepNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2155652oslo-privsep: privilege escalation vulnerability

EPSS

Процентиль: 38%
0.00171
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 3 лет назад

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVSS3: 8.8
nvd
около 3 лет назад

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVSS3: 8.8
debian
около 3 лет назад

A privilege escalation vulnerability exists in the oslo.privsep functi ...

CVSS3: 8.8
github
около 3 лет назад

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVSS3: 8.8
fstec
около 3 лет назад

Уязвимость компонента oslo.privsep платформы облачных сервисов Openstack, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 38%
0.00171
Низкий

8.8 High

CVSS3