PT-2019-2589 · Red Hat · Heketi+1

Published

2019-04-18

·

Updated

2023-02-12

·

CVE-2019-3899

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Heketi versions as shipped with Openshift Container Platform 3.11
Description The issue is related to the lack of an authentication procedure in the standard settings of Heketi, a network software tool. This could allow a remote attacker to execute arbitrary commands supported by the Heketi Server API using the Heketi CLI command-line interface.
Recommendations For Heketi versions as shipped with Openshift Container Platform 3.11, consider configuring authentication for the management interface to prevent potential misuse. As a temporary workaround, restrict access to the Heketi CLI command-line interface and the Heketi Server API until proper authentication is set up.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2019-02468
CVE-2019-3899
RHSA-2019:3255

Affected Products

Heketi
Openshift Container Platform