Vulnerability Name: | CVE-2017-2627 (CCN-148747) | ||||||||||||
Assigned: | 2016-12-01 | ||||||||||||
Published: | 2018-08-22 | ||||||||||||
Updated: | 2021-08-04 | ||||||||||||
Summary: | A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that have wildcards that allow directory traversal with '..' and it grants full passwordless root access to the validations user. | ||||||||||||
CVSS v3 Severity: | 8.2 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) 7.2 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:U/RC:R)
7.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-22 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-2627 Source: CCN Type: Red Hat Bugzilla Bug 1421917 (CVE-2017-2627) CVE-2017-2627 openstack-tripleo-common: sudoers file is too permissive Source: CONFIRM Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2627 Source: XF Type: UNKNOWN openstack-cve20172627-dir-traversal(148747) Source: CCN Type: openstack-tripleo-common GIT Repository openstack-tripleo-common Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-2627 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
BACK |