CVE-2015-1842

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
10/04/2015
Last modified:
12/04/2025

Description

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openstack:*:*:*:*:*:*:*:* 6.0 (including)