Bug 1295446 (CVE-2016-0726)

Summary: CVE-2016-0726 nagios: Configured administrative account with fixed password and no IP restriction as default
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: aavati, abaron, aortega, apevec, ayoung, carnil, chrisw, dallan, gkotton, jschluet, lhh, lpeer, markmc, mmagr, nlevinki, rbryant, rfortier, sclewis, security-response-team, sgirijan, sisharma, smohan, srevivo, ssaha, tdecacqu, tsuter, vbellur
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-05-17 06:31:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1313141, 1313142, 1313143, 1313144, 1313145    
Bug Blocks: 1295447    

Description Adam Mariš 2016-01-04 14:23:42 UTC
It was found that default configuration for nagios on Fedora is administrative account with user "nagiosadmin" with fixed password "nagiosadmin" and no IP based access restriction. This information is missing in packaged README file.

Original report:

https://bugzilla.redhat.com/show_bug.cgi?id=1295155

Comment 8 Tim Suter 2016-03-01 04:59:14 UTC
packstack,opm and director all set the password via automation, only direct package installation will contain default credentials included in the package

Comment 11 Tim Suter 2016-05-03 03:41:06 UTC
supported RHOSP installation methods are unaffected, set wontfix on products and closing trackers