Red Hat Bugzilla – Bug 1510015
CVE-2017-15114 rhosp-director: Passwordless access for non-libvirt related services when using shared certificate authority
Last modified: 2017-12-07 05:26:43 EST
It was found that if OSP-D is configured with TLS authentication for libvirtd and is using the same certificate authority for non-libvirt related services as well, these services are able to connect to libvirtd as root without any password.
Acknowledgments: Name: Daniel P. Berrange (Red Hat)
Removed embargo as the patches were made public upstream. https://review.openstack.org/#/c/519015/
External References: https://bugs.launchpad.net/tripleo/+bug/1730370