{"schema_version":"1.7.3","id":"GHSA-jx7v-gmqc-6xrj","published":"2022-05-24T17:11:21Z","modified":"2024-09-30T17:01:04.906157Z","aliases":["CVE-2020-9543","PYSEC-2020-63"],"summary":"OpenStack Manila Unprivileged users can retrieve, use and manipulate share networks","details":"OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.","affected":[{"package":{"name":"manila","ecosystem":"PyPI","purl":"pkg:pypi/manila"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.1"}]}],"versions":["4.0.2","5.0.2","5.0.3","5.1.0","6.1.0","6.2.0","6.3.0","6.3.1","6.3.2","7.0.0","7.1.0","7.2.0","7.3.0","7.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jx7v-gmqc-6xrj/GHSA-jx7v-gmqc-6xrj.json"}},{"package":{"name":"manila","ecosystem":"PyPI","purl":"pkg:pypi/manila"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.1.1"}]}],"versions":["8.0.0","8.0.1","8.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jx7v-gmqc-6xrj/GHSA-jx7v-gmqc-6xrj.json"}},{"package":{"name":"manila","ecosystem":"PyPI","purl":"pkg:pypi/manila"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.1.1"}]}],"versions":["9.0.0","9.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jx7v-gmqc-6xrj/GHSA-jx7v-gmqc-6xrj.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9543"},{"type":"WEB","url":"https://github.com/openstack/manila/commit/947315f0903c823b0fdd9d99c60078814587272c"},{"type":"WEB","url":"https://bugs.launchpad.net/manila/+bug/1861485"},{"type":"PACKAGE","url":"https://github.com/openstack/manila"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/manila/PYSEC-2020-63.yaml"},{"type":"WEB","url":"https://opendev.org/openstack/manila/commit/947315f0903c823b0fdd9d99c60078814587272c"},{"type":"WEB","url":"https://security.openstack.org/ossa/OSSA-2020-002.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2020/03/12/1"}],"database_specific":{"cwe_ids":["CWE-276"],"github_reviewed":true,"github_reviewed_at":"2024-04-29T10:21:22Z","nvd_published_at":"2020-03-12T17:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}