CVE Vulnerabilities

CVE-2017-15114

Improper Certificate Validation

Published: Nov 27, 2017 | Modified: Oct 03, 2019
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.6 IMPORTANT
CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Openstack_platform Redhat 12.0 (including) 12.0 (including)
Tripleo-heat-templates Ubuntu artful *
Tripleo-heat-templates Ubuntu bionic *
Tripleo-heat-templates Ubuntu xenial *
Tripleo-heat-templates Ubuntu zesty *

Potential Mitigations

References