Directory Traversal Vulnerability in OpenStack TripleO by Red Hat
CVE-2017-2627

8.2HIGH

Key Information:

Vendor
Red Hat
Vendor
CVE Published:
22 August 2018

Summary

A flaw in OpenStack TripleO Common, included with Red Hat OpenStack Enterprise versions 10 and 11, permits excessive permissions in the sudoers file. This misconfiguration allows the 'mistral' user to conduct directory traversal using '..', enabling unauthorized access. Furthermore, it provides the 'validations' user with full passwordless root access, posing a significant security risk to affected systems. Correcting these permissions is crucial for maintaining system integrity and security.

Affected Version(s)

openstack-tripleo-common As shipped with Red Hat Openstack Enterprise 10 and 11

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.