Bug 2155652 (CVE-2022-38065) - CVE-2022-38065 oslo-privsep: privilege escalation vulnerability
Summary: CVE-2022-38065 oslo-privsep: privilege escalation vulnerability
Keywords:
Status: NEW
Alias: CVE-2022-38065
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2155888 2155889 2155890 2155891 2155892
Blocks: 2155601
TreeView+ depends on / blocked
 
Reported: 2022-12-21 18:21 UTC by Anten Skrabec
Modified: 2023-07-07 08:35 UTC (History)
12 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A privilege escalation flaw was found in the oslo-privsep functionality in OpenStack. Overly permissive functionality in the tools leveraging this library within a container can lead to increased privileges.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Anten Skrabec 2022-12-21 18:21:51 UTC
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

Comment 2 Lon Hohberger 2022-12-21 20:59:21 UTC
The commit noted, 05194e7618, does not exist in os-brick, nova, or oslo.privsep

Comment 4 Anten Skrabec 2022-12-22 18:54:31 UTC
Created python-oslo-privsep tracking bugs for this issue:

Affects: openstack-rdo [bug 2155888]


Note You need to log in before you can comment on or make changes to this bug.