{
  "threat_severity" : "Important",
  "public_date" : "2018-06-22T00:00:00Z",
  "bugzilla" : {
    "description" : "openstack-tripleo-heat-templates: Default ODL deployment uses hard coded administrative credentials",
    "id" : "1600360",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1600360"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-798",
  "details" : [ "A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.", "When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials." ],
  "affected_release" : [ {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2018-07-19T00:00:00Z",
    "advisory" : "RHSA-2018:2214",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-tripleo-common-0:8.6.1-23.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2018-07-19T00:00:00Z",
    "advisory" : "RHSA-2018:2214",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-tripleo-heat-templates-0:8.0.2-43.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2018-07-19T00:00:00Z",
    "advisory" : "RHSA-2018:2214",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "puppet-opendaylight-0:8.1.2-2.38977efgit.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2018-07-19T00:00:00Z",
    "advisory" : "RHSA-2018:2214",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-tripleoclient-0:9.2.1-13.el7ost"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)",
    "fix_state" : "Not affected",
    "package_name" : "openstack-tripleo-heat-templates",
    "cpe" : "cpe:/a:redhat:openstack:7"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Not affected",
    "package_name" : "openstack-tripleo-heat-templates",
    "cpe" : "cpe:/a:redhat:openstack:10"
  }, {
    "product_name" : "Red Hat OpenStack Platform 11 (Ocata)",
    "fix_state" : "Not affected",
    "package_name" : "openstack-tripleo-heat-templates",
    "cpe" : "cpe:/a:redhat:openstack:11"
  }, {
    "product_name" : "Red Hat OpenStack Platform 12 (Pike)",
    "fix_state" : "Not affected",
    "package_name" : "openstack-tripleo-heat-templates",
    "cpe" : "cpe:/a:redhat:openstack:12"
  }, {
    "product_name" : "Red Hat OpenStack Platform 8 (Liberty)",
    "fix_state" : "Not affected",
    "package_name" : "openstack-tripleo-heat-templates",
    "cpe" : "cpe:/a:redhat:openstack:8"
  }, {
    "product_name" : "Red Hat OpenStack Platform 9 (Mitaka)",
    "fix_state" : "Not affected",
    "package_name" : "openstack-tripleo-heat-templates",
    "cpe" : "cpe:/a:redhat:openstack:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2018-10898\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-10898" ],
  "name" : "CVE-2018-10898",
  "csaw" : false
}