imPC@ndo IT

Tracker / CVE-2018-0041

CVE-2018-0041

Critical 9.8

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.

Affected products and versions

juniper contrail_service_orchestration · … → 3.3.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References