CVE-2019-3884: Medium severity red hat openshift vulnerability
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects.
Other sources
Creating OpenShift objects that spoof the parent UUID from another namespace can lead to deletion of valid children in that namespace.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3884?
CVE-2019-3884 is a vulnerability in the garbage collection mechanism of atomic-openshift that allows an attacker to delete children objects by spoofing the UUID of a valid object from another namespace.
Which versions of atomic-openshift are affected by CVE-2019-3884?
Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, and 4.1 of atomic-openshift are affected by CVE-2019-3884.
What is the severity of CVE-2019-3884?
CVE-2019-3884 has a severity level of low.
How can I fix CVE-2019-3884?
To fix CVE-2019-3884, update to version 4.7.0-202102060108.p0.git.97095.7271b90.el7 of openshift.
Where can I find more information about CVE-2019-3884?
More information about CVE-2019-3884 can be found at the following links: [Red Hat Security Advisory RHSA-2020:5634](https://access.redhat.com/errata/RHSA-2020:5634), [Red Hat CVE-2019-3884](https://access.redhat.com/security/cve/cve-2019-3884), [CVE-2019-3884 on CVE.org](https://www.cve.org/CVERecord?id=CVE-2019-3884), [CVE-2019-3884 on NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-3884).