CVE-2017-14178: Snapcraft Snapd

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.

Affected products

  • Snapcraft Snapd: from 2.27, up to and including 2.29.2

Published 2018-02-02. Last modified 2026-06-17.