Use of Hard-coded Credentials
CVE-2018-10898
Summary
A vulnerability was found in openstack-tripleo-heat-templates from 5.3.0 to 6.0.0, 6.0.0.0rc1 to 7.0.15, 7.0.17 to 8.0.3 and 9.0.0.0b1 to 9.0.0.0b3. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
- LOW
- ADJACENT_NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-798 - Use of Hard-coded Credentials
The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
References
Advisory Timeline
- Published