CVE Vulnerabilities

CVE-2019-3884

Authentication Bypass by Spoofing

Published: Aug 01, 2019 | Modified: Mar 03, 2023
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
3.6 LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Ubuntu

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Openshift Redhat 3.6 (including) 3.6 (including)
Openshift Redhat 3.7 (including) 3.7 (including)
Openshift Redhat 3.8 (including) 3.8 (including)
Openshift Redhat 3.9 (including) 3.9 (including)
Openshift Redhat 3.10 (including) 3.10 (including)
Openshift Redhat 3.11 (including) 3.11 (including)
Openshift Redhat 4.1 (including) 4.1 (including)
Red Hat OpenShift Container Platform 4.7 RedHat openshift-0:4.7.0-202102060108.p0.git.97095.7271b90.el7 *

References