The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of “mooo” for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
[
{
"product": "Red Hat OpenShift Enterprise",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "2.x before 2.1"
}
]
}
]