First published: Thu Jul 12 2018(Updated: )
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openstack | =13 | |
Openstack Tripleo Heat Templates | <8.0.2-40 | |
redhat/openstack-tripleo-heat-templates 8.0.2 | <40 | 40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10898 is high with a severity value of 8.8.
Redhat Openstack version 13 is affected by CVE-2018-10898.
Openstack Tripleo Heat Templates version 8.0.2-40 is vulnerable to CVE-2018-10898.
CVE-2018-10898 allows an attacker to access Opendaylight in RHOSP13 with easily guessable default credentials.
You can find more information about CVE-2018-10898 in the following references: [Reference 1](https://access.redhat.com/errata/RHSA-2018:2214), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10898), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1594328).