PT-2018-10168 · Openstack · Openstack-Tripleo-Heat-Templates

James Hebden

·

Publicado

2018-07-30

·

Atualizado

2021-08-04

·

CVE-2018-10898

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openstack-tripleo-heat-templates versions prior to 8.0.2-40
Description A vulnerability was found in openstack-tripleo-heat-templates. When deployed using Director with default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
Recommendations For versions prior to 8.0.2-40, update to version 8.0.2-40 or later to resolve the issue. As a temporary workaround, consider changing the default credentials for Opendaylight to prevent exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10898
PYSEC-2018-102
RHSA-2018:2214

Produtos afetados

Openstack-Tripleo-Heat-Templates