CRITICAL🇵🇱 Wersja polska

CVE-2014-0234

CVSS 9.8v3.1pub. 2020-02-12upd. 2024-11-21

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Red Hat Openshift

    APP
    Redhat
    < 2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2013-4561CRITICAL9.1PL ✓same product

Nieprawidłowa obsługa pliku tymczasowego w cron job węzła Red Hat OpenShift

CVE-2021-20578CRITICAL9.8PL ✓same product

IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)

CVE-2013-2060CRITICAL9.8PL ✓same product

Command Injection w OpenShift Origin przez metacharacters w URL

CVE-2014-0175CRITICAL9.8PL ✓same product

MCollective: domyślne hasło ustawiane podczas instalacji

CVE-2015-7501CRITICAL9.8PL ✓same product

RCE przez deserializację obiektów Java w produktach Red Hat (Apache Commons Collections)