Description
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0103 | OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks. |
Github GHSA |
GHSA-jx7v-gmqc-6xrj | OpenStack Manila Unprivileged users can retrieve, use and manipulate share networks |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:34:38.884Z
Reserved: 2020-03-02T00:00:00.000Z
Link: CVE-2020-9543
No data.
Status : Modified
Published: 2020-03-12T17:15:11.077
Modified: 2024-11-21T05:40:49.683
Link: CVE-2020-9543
OpenCVE Enrichment
No data.
EUVD
Github GHSA