7.3
CVSSv3

CVE-2015-5329

Published: 11/04/2016 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote malicious users to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack 7.0

Vendor Advisories

Synopsis Moderate: Red Hat Enterprise Linux OpenStack Platform 7 director update Type/Severity Security Advisory: Moderate Topic Updated packages that fix two security issues and multiple bugs are nowavailable for Red Hat Enterprise Linux OpenStack Platform 70 directorfor Red Hat Enterprise Linux 7Red Hat ...
A flaw was found in the director (openstack-tripleo-heat-templates) where the RabbitMQ credentials defaulted to guest/guest and supplied values in the configuration were not used As a result, all deployed overclouds used the same credentials (guest/guest) A remote non-authenticated attacker could use this flaw to access RabbitMQ services in the d ...