Описание
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| devel | not-affected | 1:10.0.0~b3~git2020032516.cb016333-0ubuntu1 |
| eoan | ignored | end of life |
| esm-apps/bionic | needed | |
| esm-apps/focal | not-affected | 1:10.0.0~b3~git2020032516.cb016333-0ubuntu1 |
| esm-apps/jammy | not-affected | 1:10.0.0~b3~git2020032516.cb016333-0ubuntu1 |
| esm-apps/noble | not-affected | 1:10.0.0~b3~git2020032516.cb016333-0ubuntu1 |
| esm-apps/xenial | needed | |
| esm-infra-legacy/trusty | DNE | |
| focal | not-affected | 1:10.0.0~b3~git2020032516.cb016333-0ubuntu1 |
Показывать по
Ссылки на источники
EPSS
6.5 Medium
CVSS2
8.3 High
CVSS3
Связанные уязвимости
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows att ...
OpenStack Manila Unprivileged users can retrieve, use and manipulate share networks
Уязвимость программного средства для общего доступа к файлам openstack-manila, связанная с ошибками использования стандартных разрешений, позволяющая нарушителю получить несанкционированный доступ к общим файлам
EPSS
6.5 Medium
CVSS2
8.3 High
CVSS3