First published: Fri Nov 13 2015(Updated: )
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack for IBM Power | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5329 is considered a medium severity vulnerability due to improper handling of RabbitMQ credentials.
To fix CVE-2015-5329, users should update to the latest version of the TripleO Heat templates that properly configures RabbitMQ credentials.
CVE-2015-5329 specifically affects Red Hat Enterprise Linux OpenStack Platform 7.0.
Yes, CVE-2015-5329 can potentially allow remote attackers to gain unauthorized access to services in the deployed overclouds.
CVE-2015-5329 was published on September 23, 2015.