CVE-2018-10898

Impact:
Important
Public Date:
2018-06-22
CWE:
CWE-798
Bugzilla:
1600360: CVE-2018-10898 openstack-tripleo-heat-templates: Default ODL deployment uses hard coded administrative credentials
When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.

Find out more about CVE-2018-10898 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 8.8
CVSS3 Base Metrics CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat OpenStack Platform 13.0 (Queens) (openstack-tripleo-heat-templates) RHSA-2018:2214 2018-07-19

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 9.0 openstack-tripleo-heat-templates Not affected
Red Hat OpenStack Platform 8.0 (Liberty) openstack-tripleo-heat-templates Not affected
Red Hat OpenStack Platform 12.0 openstack-tripleo-heat-templates Not affected
Red Hat OpenStack Platform 11.0 (Ocata) openstack-tripleo-heat-templates Not affected
Red Hat OpenStack Platform 10 openstack-tripleo-heat-templates Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 openstack-tripleo-heat-templates Not affected

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.