CVE-2015-5329
HIGHRed Hat Enterprise Linux OpenStack Platform 7.0 - Info Disclosure
Title source: llmDescription
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2015:2650
Scores
CVSS v3
7.3
EPSS
0.0152
EPSS Percentile
71.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-264
Status
published
Products (1)
redhat/openstack
7.0
Published
Apr 11, 2016
Tracked Since
Feb 18, 2026