The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openstack | Redhat | * | 6.0 (including) |