CVE-2017-15114

Source
https://cve.org/CVERecord?id=CVE-2017-15114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-15114
Downstream
Published
2017-11-27T16:29:00.327Z
Modified
2026-07-08T16:54:50.490421Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

References

Affected packages

Git / opendev.org/openstack/tripleo-heat-templates/

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/tripleo-heat-templates/
Events
Introduced
164b02231ecceb58d14a17fb031ba319bf96e417
Last affected
164b02231ecceb58d14a17fb031ba319bf96e417
Database specific
{
    "cpe": "cpe:2.3:a:redhat:openstack_platform:12.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "12.0"
        },
        {
            "last_affected": "12.0"
        }
    ]
}

Affected versions

12.*
12.0
12.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15114.json"