CVE-2019-3899
Last modified
CVE-2019-3899 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Container Platform | 3.11 |
| Heketi Project | Heketi | All versions |
References
- https://access.redhat.com/errata/RHSA-2019:3255Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3899Issue Tracking, Mitigation, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3255Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3899Issue Tracking, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3899?
How severe is CVE-2019-3899?
How do I fix CVE-2019-3899?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3893In Foreman it was discovered that the delete compute resourc…4.9
- CVE-2019-3894It was discovered that the ElytronManagedThread in Wildfly's…8.8
- CVE-2019-3895An access-control flaw was found in the Octavia service when…8
- CVE-2019-3896A double-free can happen in idr_remove_all() in lib/idr.c in…7
- CVE-2019-3897It has been discovered in redhat-certification that any unau…5.3
- CVE-2019-3898Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-3900An infinite loop issue was found in the vhost_net kernel mod…7.7
- CVE-2019-3901A race condition in perf_event_open() allows local attackers…4.7
- CVE-2019-3902A flaw was found in Mercurial before 4.9. It was possible to…5.1
- CVE-2019-3903Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-3905Zoho ManageEngine ADSelfService Plus 5.x before build 5703 h…
- CVE-2019-3906Premisys Identicard version 3.1.190 contains hardcoded crede…8.8
Are you affected by CVE-2019-3899?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
