Directory Traversal Vulnerability in OpenStack TripleO by Red Hat
CVE-2017-2627
8.2HIGH
What is CVE-2017-2627?
A flaw in OpenStack TripleO Common, included with Red Hat OpenStack Enterprise versions 10 and 11, permits excessive permissions in the sudoers file. This misconfiguration allows the 'mistral' user to conduct directory traversal using '..', enabling unauthorized access. Furthermore, it provides the 'validations' user with full passwordless root access, posing a significant security risk to affected systems. Correcting these permissions is crucial for maintaining system integrity and security.
Affected Version(s)
openstack-tripleo-common As shipped with Red Hat Openstack Enterprise 10 and 11