OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://bugs.launchpad.net/manila/+bug/1861485 | issue tracking exploit third party advisory |
https://security.openstack.org/ossa/OSSA-2020-002.html | patch vendor advisory |
http://www.openwall.com/lists/oss-security/2020/03/12/1 | mailing list third party advisory patch |