CVE-2019-3899: Critical severity red hat openshift container platform vulnerability
Heketi is used to manage GlusterFS nodes and volumes. The default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse.
Other sources
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3899?
CVE-2019-3899 is a vulnerability found in the default configuration of Heketi, which does not require any authentication and potentially exposes the management interface to misuse.
How does CVE-2019-3899 affect Heketi?
CVE-2019-3899 affects Heketi as shipped with Openshift Container Platform 3.11.
What is the severity of CVE-2019-3899?
CVE-2019-3899 has a severity value of 9.8 (Critical).
How can I fix CVE-2019-3899?
To fix CVE-2019-3899, it is recommended to apply the necessary patches provided by the vendor.
Where can I find more information about CVE-2019-3899?
You can find more information about CVE-2019-3899 in the references provided: [link1], [link2], [link3].