{"id":"CVE-2022-38060","aliases":["GHSA-rvxr-pf5f-j2qj","PYSEC-2026-838"],"title":"OpenStack Kolla sudo privilege escalation vulnerability","summary":"OpenStack Kolla sudo privilege escalation vulnerability","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"kolla","product":"kolla","ecosystem":"pip","affected":["kolla < 15.0.0.0rc1"],"patched":["kolla 15.0.0.0rc1"],"published":"2022-12-21","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rvxr-pf5f-j2qj","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-38060"},{"url":"https://github.com/openstack/kolla/commit/2a4a8fce31c12114e8f472c24dd96864b5bd2bd2"},{"url":"https://bugs.launchpad.net/kolla/+bug/1985784"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2124758"},{"url":"https://github.com/openstack/kolla"},{"url":"https://talosintelligence.com/vulnerability_reports/TALOS-2022-1589"}],"tags":["osv","pip"],"epss":0.00213,"epssPercentile":0.11897,"ingestedAt":"2026-07-08T18:25:53.034Z","slug":"CVE-2022-38060","body":"## Overview\n\nA privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.\n\n## Affected packages\n\n- `kolla < 15.0.0.0rc1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `kolla 15.0.0.0rc1`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}