Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15114

Опубликовано: 06 нояб. 2017
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

When libvirtd is configured by OSP director (tripleo-heat-templates) to use TLS transport, it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured, this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Directorrhosp-directorNot affected
Red Hat OpenStack Platform 10 (Newton)rhosp-directorNot affected
Red Hat OpenStack Platform 11 (Ocata)rhosp-directorNot affected
Red Hat OpenStack Platform 12 (Pike)rhosp-directorNot affected
Red Hat OpenStack Platform 8 (Liberty) Directorrhosp-directorNot affected
Red Hat OpenStack Platform 9 (Mitaka) Directorrhosp-directorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1510015rhosp-director: Passwordless access for non-libvirt related services when using shared certificate authority

EPSS

Процентиль: 75%
0.00872
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

CVSS3: 8.1
nvd
около 8 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

CVSS3: 8.1
debian
около 8 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) t ...

CVSS3: 8.1
github
больше 3 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

EPSS

Процентиль: 75%
0.00872
Низкий

7.6 High

CVSS3