CVE-2018-0041: Contrail Service Orchestration: Hardcoded credentials for Keystone service.
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0041?
CVE-2018-0041 has a high severity rating due to the use of hardcoded credentials, enabling unauthorized access to sensitive information.
How do I fix CVE-2018-0041?
To fix CVE-2018-0041, upgrade your Juniper Networks Contrail Service Orchestration to version 3.3.0 or later.
Which versions of Juniper Contrail Service Orchestration are affected by CVE-2018-0041?
CVE-2018-0041 affects all versions of Juniper Contrail Service Orchestration prior to 3.3.0.
What information is at risk due to CVE-2018-0041?
CVE-2018-0041 puts information stored in the Keystone service at risk due to unauthorized access from attackers.
Who is impacted by CVE-2018-0041?
Organizations using affected versions of Juniper Networks Contrail Service Orchestration are impacted by CVE-2018-0041.