CVE-2016-4474
Description
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- http://rhn.redhat.com/errata/RHSA-2016-1222.html
- https://access.redhat.com/security/vulnerabilities/2359821
- https://rhn.redhat.com/errata/RHSA-2016-1223.html
- http://rhn.redhat.com/errata/RHSA-2016-1222.html
- https://access.redhat.com/security/vulnerabilities/2359821
- https://rhn.redhat.com/errata/RHSA-2016-1223.html
CWEs
CWE-200 CWE-254
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.