Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.
Solution:
Workaround:
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://kb.juniper.net/JSA10872 | vendor advisory |