Severity
7.8HIGH
EPSS
0.0%
top 93.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 13

Description

FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilege may exploit this vulnerability to obtain the operation authority of some specific directory, causing privilege escalation.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-hjqc-wrmr-hq47: FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability2022-05-13
CVEList
CVE-2017-8192: FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability2017-11-22

📋Vendor Advisories

1
Red Hat
wget: Heap-based buffer overflow in HTTP protocol handling2017-10-26

💬Community

2
HackerOne
CVE-2017-13090 wget heap smash2019-11-12
Bugzilla
CVE-2017-13090 wget: Heap-based buffer overflow in HTTP protocol handling2017-10-23