Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15114

Опубликовано: 06 нояб. 2017
Источник: redhat
CVSS3: 7.6

Описание

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

When libvirtd is configured by OSP director (tripleo-heat-templates) to use TLS transport, it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured, this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Directorrhosp-directorNot affected
Red Hat OpenStack Platform 10 (Newton)rhosp-directorNot affected
Red Hat OpenStack Platform 11 (Ocata)rhosp-directorNot affected
Red Hat OpenStack Platform 12 (Pike)rhosp-directorNot affected
Red Hat OpenStack Platform 8 (Liberty) Directorrhosp-directorNot affected
Red Hat OpenStack Platform 9 (Mitaka) Directorrhosp-directorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1510015rhosp-director: Passwordless access for non-libvirt related services when using shared certificate authority

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 9 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

CVSS3: 8.1
nvd
почти 9 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

CVSS3: 8.1
debian
почти 9 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) t ...

CVSS3: 8.1
github
больше 4 лет назад

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

7.6 High

CVSS3