First published: Fri Dec 09 2016(Updated: )
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Barclamp-trove | ||
Dell Crowbar |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6829 has a moderate severity rating due to the risk of unauthorized access via default credentials.
To fix CVE-2016-6829, change the default password of the trove service user to a strong, unique password.
CVE-2016-6829 affects OpenStack deployments using the Crowbar Framework and specifically the Trove Barclamp.
Remote attackers can leverage CVE-2016-6829 by exploiting the default password to gain unauthorized access.
Failing to address CVE-2016-6829 can lead to potential data breaches and unauthorized control over the affected OpenStack deployments.