CVE Vulnerabilities

CVE-2015-1842

Published: Apr 10, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
9.3 IMPORTANT
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Openstack Redhat * 6.0 (including)
OpenStack Foreman for RHEL 6 RedHat augeas-0:1.0.0-7.el6_6.1 *
OpenStack Foreman for RHEL 6 RedHat openstack-foreman-installer-0:2.0.34-1.el6ost *
OpenStack Foreman for RHEL 6 RedHat openstack-puppet-modules-0:2014.1.2-1.el6ost *
OpenStack Foreman for RHEL 6 RedHat rhel-osp-installer-1:0.4.7-2.el6ost *
OpenStack Foreman for RHEL 6 RedHat ruby193-rubygem-staypuft-0:0.4.15-1.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat openstack-packstack-0:2014.1.1-0.46.dev1280.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat openstack-puppet-modules-0:2014.1.2-1.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat openstack-packstack-0:2014.1.1-0.46.dev1280.el7ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat openstack-puppet-modules-0:2014.1.2-1.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 Installer RedHat foreman-discovery-image-0:7.0-20150227.0.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 Installer RedHat foreman-proxy-0:1.6.0.30-6.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 Installer RedHat openstack-foreman-installer-0:3.0.22-1.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 Installer RedHat openstack-puppet-modules-0:2014.2.13-2.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 Installer RedHat rhel-osp-installer-1:0.5.7-1.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 Installer RedHat ruby193-rubygem-staypuft-0:0.5.22-1.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat openstack-packstack-0:2014.2-0.20.dev1467.g70c9655.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat openstack-puppet-modules-0:2014.2.13-2.el7ost *

References