Back

HIGH

rhosp-director: Passwordless access for non-libvirt related services when using shared certificate authority

Published Nov 27, 2017

Description

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 27, 2017
Updated Aug 5, 2024
Reserved Oct 8, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 6, 2017