Vulnerability Details CVE-2017-7549
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.2%
CVSS Severity
CVSS v3 Score 6.4
CVSS v2 Score 3.3
Products affected by CVE-2017-7549
-
cpe:2.3:a:openstack:instack-undercloud:5.3.0
-
cpe:2.3:a:openstack:instack-undercloud:6.1.0
-
cpe:2.3:a:openstack:instack-undercloud:7.2.0
-
cpe:2.3:a:redhat:openstack:10
-
cpe:2.3:a:redhat:openstack:11
-
cpe:2.3:a:redhat:openstack:12