openstack-manila: User with share-network UUID is able to show, create and delete shares
Published Mar 12, 2020
8.7
HIGHCVSS 4.0
EPSS 1.34%
Description
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
Affected products
No data.
No data.
Red Hat OpenStack Platform 13.0 (Queens)
openstack-manila-1:6.3.2-3.el7ost
Fixed · RHSA-2020:2729
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
openstack-manila-1:6.3.2-3.el7ost
Fixed · RHSA-2020:2729
Red Hat OpenStack Platform 15.0 (Stein)
openstack-manila-1:8.1.1-0.20200311070441.17b29e2.el8ost
Fixed · RHSA-2020:1326
Red Hat OpenStack Platform 16.0 (Train)
openstack-manila-1:9.1.2-0.20200405045746.f071a43.el8ost
Fixed · RHSA-2020:2165
Red Hat OpenStack Platform 10 (Newton)
openstack-manila
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-manila-1:6.3.2-3.el7ost | Fixed | RHSA-2020:2729 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | openstack-manila-1:6.3.2-3.el7ost | Fixed | RHSA-2020:2729 |
| Red Hat OpenStack Platform 15.0 (Stein) | openstack-manila-1:8.1.1-0.20200311070441.17b29e2.el8ost | Fixed | RHSA-2020:1326 |
| Red Hat OpenStack Platform 16.0 (Train) | openstack-manila-1:9.1.2-0.20200405045746.f071a43.el8ost | Fixed | RHSA-2020:2165 |
| Red Hat OpenStack Platform 10 (Newton) | openstack-manila | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
There is no known mitigation for this issue, the flaw can only be resolved by applying updates.
References (12)
- http://www.openwall.com/lists/oss-security/2020/03/12/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-9543 Vendor Advisory
- https://bugs.launchpad.net/manila/+bug/1861485 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1809855 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0103 Advisory
- https://github.com/advisories/GHSA-jx7v-gmqc-6xrj Advisory
- https://github.com/openstack/manila/commit/947315f0903c823b0fdd9d99c60078814587272c
- https://github.com/pypa/advisory-database/tree/main/vulns/manila/PYSEC-2020-63.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2020-9543
- https://opendev.org/openstack/manila/commit/947315f0903c823b0fdd9d99c60078814587272c
- https://security.openstack.org/ossa/OSSA-2020-002.html x_refsource_CONFIRMPatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9543
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2020/03/12/1 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2020-9543 | Vendor Advisory | |
| https://bugs.launchpad.net/manila/+bug/1861485 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1809855 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0103 | Advisory | |
| https://github.com/advisories/GHSA-jx7v-gmqc-6xrj | Advisory | |
| https://github.com/openstack/manila/commit/947315f0903c823b0fdd9d99c60078814587272c | ||
| https://github.com/pypa/advisory-database/tree/main/vulns/manila/PYSEC-2020-63.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-9543 | ||
| https://opendev.org/openstack/manila/commit/947315f0903c823b0fdd9d99c60078814587272c | ||
| https://security.openstack.org/ossa/OSSA-2020-002.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-9543 |
Change history (0)
No recorded changes yet.