The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRed Hat Openshift
APPRedhat< 2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2013-4561CRITICAL9.1PL ✓same product
Nieprawidłowa obsługa pliku tymczasowego w cron job węzła Red Hat OpenShift
CVE-2021-20578CRITICAL9.8PL ✓same product
IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)
CVE-2013-2060CRITICAL9.8PL ✓same product
Command Injection w OpenShift Origin przez metacharacters w URL
CVE-2014-0175CRITICAL9.8PL ✓same product
MCollective: domyślne hasło ustawiane podczas instalacji
CVE-2015-7501CRITICAL9.8PL ✓same product
RCE przez deserializację obiektów Java w produktach Red Hat (Apache Commons Collections)