CVE-2014-0234

CRITICAL

Red Hat OpenShift Enterprise <2.1 - RCE

Title source: llm
STIX 2.1

Description

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

References (5)

Core 5
Core References
Exploit, Mailing List, Patch, Third Party Advisory x_refsource_misc
http://openwall.com/lists/oss-security/2014/06/05/19
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1097008
Vendor Advisory x_refsource_misc
https://rhn.redhat.com/errata/RHSA-2014-0487.html
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/67657

Scores

CVSS v3 9.8
EPSS 0.0370
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1188
Status published
Products (1)
redhat/openshift < 2.1
Published Feb 12, 2020
Tracked Since Feb 18, 2026