cvedb.io
CVE-2022-22189
HIGH · CVSS 7.3
EPSS exploitation probability: 0%
Published 2022-04-14T16:15:08.167 · Last modified 2026-06-17T04:27:57.830

Summary

An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking control of the local system they are currently authenticated to. This issue affects: Juniper Networks Contrail Service Orchestration 6.0.0 versions prior to 6.0.0 Patch v3 on On-premises installations. This issue does not affect Juniper Networks Contrail Service Orchestration On-premises versions prior to 6.0.0.

Affected products

juniper — contrail_service_orchestration

Does this affect you?

Add your gear to cvedb and we'll alert you only when juniper ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.