The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1842
Reference (s):
- BID:74049
- URL: http://www.securityfocus.com/bid/74049
- https://bugzilla.redhat.com/show_bug.cgi?id=1201875
- REDHAT:RHSA-2015:0789
- URL: http://rhn.redhat.com/errata/RHSA-2015-0789.html

