Contrail Service Orchestration: An authenticated local user may have their permissions elevated via the device via management interface without authentication
Published Apr 14, 2022
7.8
HIGHCVSS 3.1
EPSS 0.23%
Description
An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking control of the local system they are currently authenticated to. This issue affects: Juniper Networks Contrail Service Orchestration 6.0.0 versions prior to 6.0.0 Patch v3 on On-premises installations. This issue does not affect Juniper Networks Contrail Service Orchestration On-premises versions prior to 6.0.0.
Affected products
-
- Version 6.0.0StatusaffectedConstraints<6.0.0 Patch v3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Contrail Service Orchestration | n/a |
|
- 6.0.0
- 6.0.0
- 6.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve these specific issues: On-premises: Contrail Service Orchestration 6.0.0 Patch v3, 6.1.0, and all subsequent releases.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27336 Advisory
- https://kb.juniper.net/JSA69498 x_refsource_CONFIRMPermissions RequiredVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27336 | Advisory | |
| https://kb.juniper.net/JSA69498 | x_refsource_CONFIRMPermissions RequiredVendor Advisory |
Change history (0)
No recorded changes yet.