{"id":"CVE-2020-9543","aliases":["GHSA-jx7v-gmqc-6xrj","PYSEC-2020-63"],"url":"https://o3.security/vulnerability/CVE-2020-9543","summary":"OpenStack Manila Unprivileged users can retrieve, use and manipulate share networks","details":"OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.","published":"2020-03-12T17:15:11.077Z","modified":"2026-04-10T04:28:43.799653Z","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"manila","fixedVersion":"7.4.1"},{"ecosystem":"PyPI","name":"manila","fixedVersion":"8.1.1"},{"ecosystem":"PyPI","name":"manila","fixedVersion":"9.1.1"}],"fix":null,"references":[{"type":"REPORT","url":"https://bugs.launchpad.net/manila/+bug/1861485"},{"type":"FIX","url":"https://security.openstack.org/ossa/OSSA-2020-002.html"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2020/03/12/1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T04:28:43.799653Z"}}