High severity8.1NVD Advisory· Published Nov 27, 2017· Updated May 13, 2026
CVE-2017-15114
CVE-2017-15114
Description
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.
Affected products
1- cpe:2.3:a:redhat:openstack_platform:12.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- git.openstack.org/cgit/openstack/tripleo-heat-templates/commit/nvdPatchVendor Advisory
- www.securityfocus.com/bid/101971nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.