CVE-2020-9543: High severity Openstack Manila vulnerability
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/manilato a version that resolves this vulnerability.Fixed in 9.1.1 - Upgrade
Upgrade
pip/manilato a version that resolves this vulnerability.Fixed in 8.1.1 - Upgrade
Upgrade
pip/manilato a version that resolves this vulnerability.Fixed in 7.4.1 - Upgrade
Upgrade
OpenStack Manilato a version that resolves this vulnerability.Fixed in 7.4.1 - Upgrade
Upgrade
OpenStack Manilato a version that resolves this vulnerability.Fixed in 8.1.1 - Upgrade
Upgrade
OpenStack Manilato a version that resolves this vulnerability.Fixed in 9.1.1
Event History
Frequently Asked Questions
What is the vulnerability ID for OpenStack Manila?
The vulnerability ID for OpenStack Manila is CVE-2020-9543.
What are the affected software versions for this vulnerability?
The affected software versions for this vulnerability are OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1.
What is the severity level of CVE-2020-9543?
The severity level of CVE-2020-9543 is high.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability to view, update, delete, or share resources that do not belong to them, as well as create resources.
Where can I find more information about CVE-2020-9543?
You can find more information about CVE-2020-9543 at the following references: http://www.openwall.com/lists/oss-security/2020/03/12/1, https://bugs.launchpad.net/manila/+bug/1861485, and https://security.openstack.org/ossa/OSSA-2020-002.html.