CVE-2017-2627 Vulnerability Details

  /     /     /  

CVE-2017-2627 Metadata Quick Info

CVE Published: 22/08/2018 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: redhat | Vendor: Red Hat | Product: openstack-tripleo-common
Status : PUBLISHED

CVE-2017-2627 Description

A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP\'s openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that have wildcards that allow directory traversal with \'..\' and it grants full passwordless root access to the validations user.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-22
CWE Name: CWE-22
Source: Red Hat

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).