CVE-2019-14819: High severity red hat openshift container platform vulnerability
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14819?
CVE-2019-14819 is categorized as a medium severity vulnerability.
How do I fix CVE-2019-14819?
To fix CVE-2019-14819, it is recommended to upgrade your Red Hat OpenShift Container Platform to versions 3.10.50 or later, or 3.11.39 or later.
Who is affected by CVE-2019-14819?
CVE-2019-14819 affects users of Red Hat OpenShift Container Platform version 3.10 and 3.11.
What types of exploits can occur due to CVE-2019-14819?
CVE-2019-14819 can allow unprivileged users to escalate their privileges within the OpenShift environment.
Is there a workaround for CVE-2019-14819?
While the primary mitigation for CVE-2019-14819 is upgrading, limiting user permissions can also help reduce risks.