Database/Control plane, storage & DevOps

Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions through
CVE-2019-18181Control plane, storage & DevOpscurated
Impact
A read-only CloudVision user escapes their permissions through Configlet Builder API calls and can execute restricted functionality. Read-only accounts are the ones handed out most freely — dashboards, auditors, tenant liaisons — so this is a large-blast-radius privilege escalation on the fabric controller.
Who can reach it
Any authenticated read-only CVP user with API access.
What to do
CloudVision Portal upgrade. Controller-side, no switch impact. Review Configlet Builder execution history for anything run by a read-only principal.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.