First published: Fri Mar 13 2015(Updated: )
It was discovered that openstack-puppet-modules as used by the Red Hat Enterprise Linux OpenStack Platform Installers would always use the default password of "CHANGEME" when deploying pcsd in HA environments.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack for IBM Power | <=6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-1842 is considered high due to the use of a default password, allowing unauthorized access.
To fix CVE-2015-1842, change the default password from "CHANGEME" to a secure password during the deployment of pcsd.
CVE-2015-1842 affects Red Hat OpenStack versions prior to 2014.2.13-2.
CVE-2015-1842 impacts high availability (HA) environments using openstack-puppet-modules.
A temporary workaround for CVE-2015-1842 is to manually configure the pcsd password immediately after deployment.