SB2017062022 - Red Hat update for Red Hat OpenStack Platform director
Published: June 20, 2017
Security Bulletin ID
SB2017062022
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass (CVE-ID: CVE-2017-2637)
The vulnerability allows a remote unauthenticated attacker to bypass authentication on a targeted system.The weakness exists due to the improper authentication and encryption standards that are set by default when the libvirtd component is deployed by the affected software. A remote attacker create a TCP connection to a compute host IP address, gain unauthorized access to the system that may allow to gain control of the host.
Successful exploitation of the vulnerability results in unauthorized access to the system.
Remediation
Install update from vendor's website.