The official RHEL and Fedora base images use a default root password.
Acknowledgements: This issue was discovered by Colin Walters of Red Hat.
This is not released yet so no need for a CVE as long as we fix it before it ships.
Rawhide commit: https://git.fedorahosted.org/cgit/spin-kickstarts.git/commit/?id=6ba647a663f09da4ba740eb99733a39cba58d204