Source: python-oslo.privsep
X-Debbugs-CC: t...@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for python-oslo.privsep.

CVE-2022-38065[0]:
| A privilege escalation vulnerability exists in the oslo.privsep
| functionality of OpenStack git master 05194e7618 and prior. Overly
| permissive functionality within tools leveraging this library within a
| container can lead increased privileges.

This originates from 
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1599
but it looks a little murky, since there's no commit 05194e7618 in the
upstream repo, probably best to reach out to upstream for details?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-38065
    https://www.cve.org/CVERecord?id=CVE-2022-38065

Please adjust the affected versions in the BTS as needed.

Reply via email to