Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1842

Опубликовано: 10 мар. 2015
Источник: redhat
CVSS2: 9.3
EPSS Низкий

Описание

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.

It was discovered that the puppet manifests, as provided with the openstack-puppet-modules package, would configure the pcsd daemon with a known default password. If this password was not changed and an attacker was able to gain access to pcsd, they could potentially run shell commands as root.

Отчет

Red Hat Product Security has rated this issue as having Important security impact, a future update will address the flaw. As a mitigation against this issue, any system deployed using the affected component should have the 'hacluster' password changed before being placed into production or on an untrusted network. An article with more detailed information is available to customers here: https://access.redhat.com/articles/1396123

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4openstack-foreman-installerAffected
Red Hat OpenStack Platform 4openstack-puppet-modulesAffected
OpenStack Foreman for RHEL 6augeasFixedRHSA-2015:083016.04.2015
OpenStack Foreman for RHEL 6openstack-foreman-installerFixedRHSA-2015:083016.04.2015
OpenStack Foreman for RHEL 6openstack-puppet-modulesFixedRHSA-2015:083016.04.2015
OpenStack Foreman for RHEL 6rhel-osp-installerFixedRHSA-2015:083016.04.2015
OpenStack Foreman for RHEL 6ruby193-rubygem-staypuftFixedRHSA-2015:083016.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-packstackFixedRHSA-2015:083216.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-puppet-modulesFixedRHSA-2015:083216.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-packstackFixedRHSA-2015:083116.04.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-798
https://bugzilla.redhat.com/show_bug.cgi?id=1201875openstack-puppet-modules: pacemaker configured with default password

EPSS

Процентиль: 89%
0.04844
Низкий

9.3 Critical

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.

github
больше 3 лет назад

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.

fstec
почти 11 лет назад

Уязвимость платформы облачных сервисов Openstack, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 89%
0.04844
Низкий

9.3 Critical

CVSS2