CRITICAL🇵🇱 Wersja polska

CVE-2019-3899

CVSS 9.8v3.1pub. 2019-04-22upd. 2024-11-21

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Heketi Project Heketi

    APP
    Heketi Project
    all versions
  • Red Hat OpenShift Container Platform

    APP
    Redhat
    3.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product

RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu

CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)

CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE

CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product

RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework

CVE-2026-4408CRITICAL9.0PL ✓same product

Samba: RCE przez command injection w 'check password script' z podstawieniem %u