CVE-2016-4474: Infoleak
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4474?
CVE-2016-4474 is considered a high severity vulnerability due to the use of a default root password, which can lead to unauthorized access.
How do I fix CVE-2016-4474?
To fix CVE-2016-4474, change the default root password from ROOTPW to a strong, unique password.
Which versions of OpenStack are affected by CVE-2016-4474?
CVE-2016-4474 affects Red Hat OpenStack Platform 7.0 and 8.0.
What can be exploited in CVE-2016-4474?
CVE-2016-4474 can be exploited to gain unauthorized access to systems by leveraging the default root password.
Is there a workaround for CVE-2016-4474?
The primary workaround for CVE-2016-4474 is to immediately update the default root password to prevent unauthorized access.