It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHeketi Project Heketi
APPHeketi Projectall versionsRed Hat OpenShift Container Platform
APPRedhat3.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
Related vulnerabilities
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework
CVE-2026-4408CRITICAL9.0PL ✓same product
Samba: RCE przez command injection w 'check password script' z podstawieniem %u