Improper access control in CRI-O - CVE-2022-2995
Published: August 30, 2022
Vulnerability identifier: #VU66817
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2995
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to incorrect handling of the supplementary groups. A local user can bypass implemented security restrictions, leading to sensitive information disclosure or possible data modification.
Affected software
CRI-O
OpenShift Service Mesh
containerd
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Ansible Automation Platform
Red Hat Migration Toolkit for Applications
openEuler
python-flask (Red Hat package)
cri-o-debugsource
cri-o-debuginfo
cri-o
cri-o (Red Hat package)
jenkins (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
openstack-ironic (Red Hat package)
OpenShift Service Mesh
containerd
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Ansible Automation Platform
Red Hat Migration Toolkit for Applications
openEuler
python-flask (Red Hat package)
cri-o-debugsource
cri-o-debuginfo
cri-o
cri-o (Red Hat package)
jenkins (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
openstack-ironic (Red Hat package)
How to mitigate CVE-2022-2995
Install updates from vendor's website.
CRI-O - addressed in versions 1.25.0, 1.24.5
containerd - addressed in versions 1.5.18, 1.6.18
Migration Toolkit for Containers - addressed in versions 1.7.7, 1.7.8
Red Hat OpenShift Container Platform - addressed in versions 4.10.60, 4.11.43, 4.11.44, 4.12.0
Red Hat Migration Toolkit for Applications - update to 6.1.0
python-flask (Red Hat package) - update to 1.1.2-6.el8
cri-o-debugsource - update to 1.23.2-2
cri-o-debuginfo - update to 1.23.2-2
cri-o - update to 1.23.2-2
cri-o (Red Hat package) - addressed in versions 1.23.5-11.rhaos4.10.gitfc32aac.el7, 1.23.5-11.rhaos4.10.gitfc32aac.el8, 1.24.5-5.rhaos4.11.git8bf967b.el8
OpenShift Service Mesh - update to 2.4.0
jenkins (Red Hat package) - update to 2.387.3.1684251986-1.el8
openshift-kuryr (Red Hat package) - update to 4.10.0-202305161315.p0.g8e4df8b.assembly.stream.el8
openshift (Red Hat package) - update to 4.11.0-202305261554.p0.g38b1413.assembly.stream.el8
openstack-ironic (Red Hat package) - update to 20.2.1-0.20230605115028.483a7f9.el8
containerd - addressed in versions 1.5.18, 1.6.18
Migration Toolkit for Containers - addressed in versions 1.7.7, 1.7.8
Red Hat OpenShift Container Platform - addressed in versions 4.10.60, 4.11.43, 4.11.44, 4.12.0
Red Hat Migration Toolkit for Applications - update to 6.1.0
python-flask (Red Hat package) - update to 1.1.2-6.el8
cri-o-debugsource - update to 1.23.2-2
cri-o-debuginfo - update to 1.23.2-2
cri-o - update to 1.23.2-2
cri-o (Red Hat package) - addressed in versions 1.23.5-11.rhaos4.10.gitfc32aac.el7, 1.23.5-11.rhaos4.10.gitfc32aac.el8, 1.24.5-5.rhaos4.11.git8bf967b.el8
OpenShift Service Mesh - update to 2.4.0
jenkins (Red Hat package) - update to 2.387.3.1684251986-1.el8
openshift-kuryr (Red Hat package) - update to 4.10.0-202305161315.p0.g8e4df8b.assembly.stream.el8
openshift (Red Hat package) - update to 4.11.0-202305261554.p0.g38b1413.assembly.stream.el8
openstack-ironic (Red Hat package) - update to 20.2.1-0.20230605115028.483a7f9.el8
External References
Related Security Bulletins
- Improper access control in cri-o
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in containerd
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in CRI-O
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- OpenShift Container Platform 4.10 update for CRI-O
- OpenShift Container Platform 4.11 update for cri-o
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.4
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- openEuler 22.03 LTS SP1 update for cri-o
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4 for RHEL 9