CVE-2014-0234: Red Hat Openshift

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

Affected products

  • Red Hat Openshift: before 2.1 (fixed in 2.1)

Published 2020-02-12. Last modified 2026-06-17.