First published: Fri May 17 2019(Updated: )
IBM Cloud Private Kubernetes API server 2.1.0, 3.1.0, 3.1.1, and 3.1.2 can be used as an HTTP proxy to not only cluster internal but also external target IP addresses. IBM X-Force ID: 158145.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Private | >=2.1.0.0<=2.1.0.3 | |
IBM Cloud Private | =3.1.0 | |
IBM Cloud Private | =3.1.1 | |
IBM Cloud Private | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4119 is medium with a severity value of 5.3.
IBM Cloud Private Kubernetes API server 2.1.0, 3.1.0, 3.1.1, and 3.1.2 can be used as an HTTP proxy to not only cluster internal but also external target IP addresses.
The IBM X-Force ID for CVE-2019-4119 is 158145.
The affected software versions for CVE-2019-4119 are IBM Cloud Private Kubernetes API server 2.1.0 (between 2.1.0.0 and 2.1.0.3), 3.1.0, 3.1.1, and 3.1.2.
You can find more information about CVE-2019-4119 on the IBM support website (http://www.ibm.com/support/docview.wss?uid=ibm10878460) and IBM X-Force (https://exchange.xforce.ibmcloud.com/vulnerabilities/158145).