VulnerabilityModified
CVE-2019-3899
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse.
CRITICAL 9.8EPSS 1.41%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-592, CWE-306
- Affected
- redhat/openshift container platform · heketi project/heketi
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2019:3255Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3899Issue Tracking, Mitigation, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3255Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3899Issue Tracking, Mitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.