Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0234

Опубликовано: 14 мая 2014
Источник: redhat
CVSS2: 7.5
EPSS Низкий

Описание

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

Дополнительная информация

Статус:

Important
Дефект:
CWE-798
https://bugzilla.redhat.com/show_bug.cgi?id=1097008openshift-origin-broker: default password creation

EPSS

Процентиль: 80%
0.01422
Низкий

7.5 High

CVSS2

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

CVSS3: 9.8
github
больше 3 лет назад

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

EPSS

Процентиль: 80%
0.01422
Низкий

7.5 High

CVSS2