CVE Vulnerabilities

CVE-2019-3884

Authentication Bypass by Spoofing

Published: Aug 01, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
3.6 LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

NameVendorStart VersionEnd Version
OpenshiftRedhat3.6 (including)3.6 (including)
OpenshiftRedhat3.7 (including)3.7 (including)
OpenshiftRedhat3.8 (including)3.8 (including)
OpenshiftRedhat3.9 (including)3.9 (including)
OpenshiftRedhat3.10 (including)3.10 (including)
OpenshiftRedhat3.11 (including)3.11 (including)
OpenshiftRedhat4.1 (including)4.1 (including)
Red Hat OpenShift Container Platform 4.7RedHatopenshift-0:4.7.0-202102060108.p0.git.97095.7271b90.el7*

References