First published: Mon Nov 27 2017(Updated: )
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openstack Platform | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15114 is a vulnerability in libvirtd when configured to use the TLS transport without additional authentication.
Redhat Openstack Platform 12.0 is affected by CVE-2017-15114 if libvirtd is configured to use the TLS transport.
The severity of CVE-2017-15114 is critical (8.1).
To fix CVE-2017-15114, apply the patch provided in the reference link.
You can find more information about CVE-2017-15114 in the reference links provided.