The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
References
Configurations
History
21 Nov 2024, 02:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2015-0789.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-0791.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-0830.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2015-0831.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2015-0832.html - | |
References | () http://www.securityfocus.com/bid/74049 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1201875 - |
Information
Published : 2015-04-10 15:00
Updated : 2024-11-21 02:26
NVD link : CVE-2015-1842
Mitre link : CVE-2015-1842
CVE.ORG link : CVE-2015-1842
JSON object : View
Products Affected
redhat
- openstack
CWE
CWE-255
Credentials Management Errors