OpenStack oslo.privsep PrivEsc via Overly Permissive Access
CVE-2022-38065 Published on December 21, 2022

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

NVD

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2022-38065

Want to know whenever a new CVE is published for Red Hat Openstack? stack.watch will email you.

 

Affected Versions

OpenStack Version git master 05194e7618 is affected by CVE-2022-38065

Exploit Probability

EPSS
0.17%
Percentile
38.19%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.