CVE-2018-10898
published 2018-07-30CVE-2018-10898: A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight…
PriorityP342high8.8CVSS 3.0
AVAACLPRNUINSUCHIHAH
EPSS
0.87%
54.5th percentile
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | tripleo_heat_templates | < 8.0.2-40 | 8.0.2-40 |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-tripleo-heat-templates: Default ODL deployment uses hard coded administrative credentials
vendor_redhat·2018-06-22·CVSS 8.8
CVE-2018-10898 [HIGH] CWE-798 openstack-tripleo-heat-templates: Default ODL deployment uses hard coded administrative credentials
openstack-tripleo-heat-templates: Default ODL deployment uses hard coded administrative credentials
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
Package: openstack-tripleo-heat-templates (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not affected
Package: openstack-tripleo-heat-templates (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: openstack-tripleo-heat-templates (Red Hat OpenStack Platform 11 (Ocata)) - Not affected
Package: openstack-tri
GHSA
GHSA-9xj4-8jr9-rf9f: A vulnerability was found in openstack-tripleo-heat-templates before version 8
ghsa_unreviewed·2022-05-13
CVE-2018-10898 [HIGH] CWE-798 GHSA-9xj4-8jr9-rf9f: A vulnerability was found in openstack-tripleo-heat-templates before version 8
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
OSV
CVE-2018-10898: A vulnerability was found in openstack-tripleo-heat-templates before version 8
osv·2018-07-30
CVE-2018-10898 CVE-2018-10898: A vulnerability was found in openstack-tripleo-heat-templates before version 8
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
No detection rules found.
No public exploits indexed.
2018-07-30
Published