CVE-2017-15114

Source
https://cve.org/CVERecord?id=CVE-2017-15114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-15114
Downstream
Published
2017-11-27T16:29:00.327Z
Modified
2026-04-10T03:57:36.955460Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

References

Affected packages

Git / opendev.org/openstack/tripleo-heat-templates/

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/tripleo-heat-templates/
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
164b02231ecceb58d14a17fb031ba319bf96e417
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "12.0"
        }
    ]
}

Affected versions

0.*
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
1.*
1.0.0
10.*
10.0.0
10.1.0
10.2.0
10.3.0
10.4.0
10.5.0
11.*
11.0.0
11.1.0
11.2.0
11.3.0
12.*
12.0.0
2.*
2.0.0
5.*
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
6.*
6.0.0.0b1
6.0.0.0b2
6.0.0.0rc1
7.*
7.0.0.0b1
7.0.0.0b2
7.0.0.0b3
7.0.0.0rc1
8.*
8.0.0.0b1
8.0.0.0b2
8.0.0.0b3
8.0.0.0rc1
9.*
9.0.0.0b2
9.0.0.0b3
9.0.0.0b4
9.0.0.0rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15114.json"