Vulnerability CVE-2018-9090


Published: 2019-09-24

Description:
CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to later be configured by Tectonic administrators. An attacker can insert an XSS payload into the dashboards.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

Vendor: Redhat
Product: Tectonic 
Version:
1.8.4-tectonic.4
1.8.4-tectonic.3
1.8.4-tectonic.2
1.8.4-tectonic.1
1.7.9-tectonic.4
1.7.9-tectonic.3
1.7.9-tectonic.2
1.7.9-tectonic.1
1.7.5-tectonic.1
1.7.3-tectonic.4
1.7.3-tectonic.3
1.7.3-tectonic.2
1.7.3-tectonic.1
1.7.14-tectonic.2
1.7.14-tectonic.1
1.7.1-tectonic.2
1.7.1-tectonic.1.0.0
1.7.1-tectonic.1

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
https://coreos.com/tectonic/releases/
https://coreos.com/tectonic/releases/#1.8.7-tectonic.2

Related CVE
CVE-2014-8167
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
CVE-2014-3655
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
CVE-2014-3592
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
CVE-2010-3857
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
CVE-2014-3599
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
CVE-2011-2897
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
CVE-2019-14860
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
CVE-2019-14824
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

Copyright 2019, cxsecurity.com

 

Back to Top