CVE Vulnerabilities

CVE-2019-3899

DEPRECATED: Authentication Bypass Issues

Published: Apr 22, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

Weakness

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

Affected Software

NameVendorStart VersionEnd Version
Openshift_container_platformRedhat3.11 (including)3.11 (including)
Native Client for RHEL 7 for Red Hat StorageRedHatheketi-0:9.0.0-7.el7rhgs*
Red Hat Gluster Storage 3.5 for RHEL 7RedHatheketi-0:9.0.0-7.el7rhgs*

References