PT-2018-10168 · Openstack · Openstack-Tripleo-Heat-Templates
James Hebden
·
Publicado
2018-07-30
·
Atualizado
2021-08-04
·
CVE-2018-10898
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openstack-tripleo-heat-templates versions prior to 8.0.2-40
Description
A vulnerability was found in openstack-tripleo-heat-templates. When deployed using Director with default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
Recommendations
For versions prior to 8.0.2-40, update to version 8.0.2-40 or later to resolve the issue. As a temporary workaround, consider changing the default credentials for Opendaylight to prevent exploitation.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openstack-Tripleo-Heat-Templates