CVE-2017-2627
Description
A permissive sudoers file in openstack-tripleo-common allows directory traversal and passwordless root access on Red Hat OpenStack Platform 10 and 11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A permissive sudoers file in openstack-tripleo-common allows directory traversal and passwordless root access on Red Hat OpenStack Platform 10 and 11.
Vulnerability
The sudoers file installed with the openstack-tripleo-common package in Red Hat OpenStack Platform (OSP) versions 10 and 11 is overly permissive [1]. It contains lines for the mistral user that use wildcards enabling directory traversal via .. sequences, and it grants full passwordless root access to the validations user [1].
Exploitation
An attacker who gains access as the mistral user can exploit the directory traversal wildcards in the sudoers file to execute arbitrary commands as root with sudo. Alternatively, an attacker who obtains the validations account can simply run sudo to gain a root shell without providing a password [1].
Impact
Successful exploitation results in complete system compromise: an attacker gains full root privileges, allowing them to read, modify, or delete any data, install software, and pivot to other systems on the network.
Mitigation
Red Hat released updated openstack-tripleo-common packages for OSP 10 and 11 that restrict the sudoers entries. Users should update to the latest available version. No workaround is available; the issue is fixed only via the package update [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: =10, 11
(expand)+ 1 more
- (no CPE)
- (no CPE)range: As shipped with Red Hat Openstack Enterprise 10 and 11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.