CVE-2017-14178

HIGH

snapd 2.27-2.29.2 - Unauthenticated Access Restriction Bypass via 'snap logs' Command

Title source: llm
STIX 2.1

Description

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.

References (3)

Core 3
Core References
Issue Tracking, Patch x_refsource_confirm
https://launchpad.net/bugs/1730255
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/snapcore/snapd/pull/4194

Scores

CVSS v3 7.5
EPSS 0.0179
EPSS Percentile 75.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-755
Status published
Products (1)
snapcraft/snapd 2.27 - 2.29.2
Published Feb 02, 2018
Tracked Since Feb 18, 2026