CVE-2018-0041

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
11/07/2018
Last modified:
09/10/2019

Description

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:juniper:contrail_service_orchestration:*:*:*:*:*:*:*:* 3.3.0 (excluding)


References to Advisories, Solutions, and Tools