Описание
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-0234
- https://access.redhat.com/errata/RHBA-2014:0487
- https://access.redhat.com/security/cve/CVE-2014-0234
- https://bugzilla.redhat.com/show_bug.cgi?id=1097008
- https://github.com/openshift/openshift-extras/blob/master/README.md
- https://rhn.redhat.com/errata/RHSA-2014-0487.html
- http://openwall.com/lists/oss-security/2014/06/05/19
- http://www.securityfocus.com/bid/67657
Связанные уязвимости
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.