PT-2019-2589 · Red Hat · Heketi+1
CVE-2019-3899
·
Publicado
2019-04-18
·
Atualizado
2023-02-12
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Heketi versions as shipped with Openshift Container Platform 3.11
Description
The issue is related to the lack of an authentication procedure in the standard settings of Heketi, a network software tool. This could allow a remote attacker to execute arbitrary commands supported by the Heketi Server API using the Heketi CLI command-line interface.
Recommendations
For Heketi versions as shipped with Openshift Container Platform 3.11, consider configuring authentication for the management interface to prevent potential misuse. As a temporary workaround, restrict access to the Heketi CLI command-line interface and the Heketi Server API until proper authentication is set up.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Heketi
Openshift Container Platform