CVE-2019-3899 Vulnerability Details

  /     /     /  

CVE-2019-3899 Metadata Quick Info

CVE Published: 22/04/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: redhat | Vendor: The Heketi Project | Product: heketi
Status : PUBLISHED

CVE-2019-3899 Description

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-592
CWE Name: CWE-592
Source: The Heketi Project

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).