{"id":"CVE-2022-38060","aliases":["PYSEC-2026-838"],"url":"https://o3.security/vulnerability/CVE-2022-38060","summary":"OpenStack Kolla sudo privilege escalation vulnerability","details":"A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.","published":"2022-12-21T12:30:24Z","modified":"2026-07-07T11:56:29.911820876Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"kolla","fixedVersion":"15.0.0.0rc1"}],"fix":{"url":"https://github.com/openstack/kolla/commit/2a4a8fce31c12114e8f472c24dd96864b5bd2bd2","label":"openstack/kolla@2a4a8fc"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-38060"},{"type":"WEB","url":"https://github.com/openstack/kolla/commit/2a4a8fce31c12114e8f472c24dd96864b5bd2bd2"},{"type":"WEB","url":"https://bugs.launchpad.net/kolla/+bug/1985784"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2124758"},{"type":"WEB","url":"https://github.com/openstack/kolla"},{"type":"WEB","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2022-1589"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T11:56:29.911820876Z"}}