---
cve: "CVE-2018-9090"
severity: "LOW"
cvss: 3.1
epss: "79%"
vendor: "n/a"
kev: false
exploited: false
published: "2019-09-24 14:15:11"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T11:27:47+02:00"
---

# CVE-2018-9090

> 3.1 LOW

## Beschreibung

CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to later be configured by Tectonic administrators. An attacker can insert an XSS payload into the dashboards.

## Referenzen

- <https://coreos.com/tectonic/releases/>
- <https://coreos.com/tectonic/releases/#1.8.7-tectonic.2>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-9090) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
