The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://rhn.redhat.com/errata/RHSA-2016-1223.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2016-1222.html | vendor advisory |
https://access.redhat.com/security/vulnerabilities/2359821 | vendor advisory |