Skip to main content

Use of Hard-coded Credentials

CVE-2018-10898

Severity High
Score 8.8/10

Summary

A vulnerability was found in openstack-tripleo-heat-templates from 5.3.0 to 6.0.0, 6.0.0.0rc1 to 7.0.15, 7.0.17 to 8.0.3 and 9.0.0.0b1 to 9.0.0.0b3. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.

  • LOW
  • ADJACENT_NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-798 - Use of Hard-coded Credentials

The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

References

Advisory Timeline

  • Published