CVE-2015-5329: High severity red hat openstack for ibm power vulnerability
A vulnerability in openstack-tripleo-heat-templates was found, which regardless of supplied values for credentials uses hardcoded rabbitmq credentails to guest/guest account. In the documentation users are strongly encouraged to change the default values for credentials, however changing these values using our instructions does not correctly set the values in the rabbitmq config.
Other sources
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5329?
CVE-2015-5329 is considered a medium severity vulnerability due to improper handling of RabbitMQ credentials.
How do I fix CVE-2015-5329?
To fix CVE-2015-5329, users should update to the latest version of the TripleO Heat templates that properly configures RabbitMQ credentials.
What systems are affected by CVE-2015-5329?
CVE-2015-5329 specifically affects Red Hat Enterprise Linux OpenStack Platform 7.0.
Can CVE-2015-5329 lead to unauthorized access?
Yes, CVE-2015-5329 can potentially allow remote attackers to gain unauthorized access to services in the deployed overclouds.
When was CVE-2015-5329 published?
CVE-2015-5329 was published on September 23, 2015.