Описание
An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.
A flaw was found in Fluentd and fluent-ui. This issue may allow an attacker to gain escalated privileges and execute arbitrary code due to allowing a default password at install time.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | fluentd | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-fluentd | Not affected | ||
| Red Hat OpenStack Platform 13 (Queens) Operational Tools | fluentd | Not affected | ||
| Red Hat Virtualization 4 | fluentd | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.
Fluent Fluentd and Fluent-ui use default password
Уязвимость сборщика данных Fluent Fluentd и его браузерного менеджера fluentd-ui, связанная с использованием по умолчанию стандартного пароля, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3