CVE-2019-3884
published 2019-08-01CVE-2019-3884: A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.62%
46.1th percentile
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | atomic-openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv3.03.6LOWCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
atomic-openshift: cross-namespace owner references can trigger deletions of valid children
vendor_redhat·2019-03-29·CVSS 5.4
CVE-2019-3884 [MEDIUM] CWE-290 atomic-openshift: cross-namespace owner references can trigger deletions of valid children
atomic-openshift: cross-namespace owner references can trigger deletions of valid children
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects.
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.10) - Fix deferred
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.11) - Fix deferred
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.4) - Not a
GHSA
GHSA-fpgq-qv2c-6787: A vulnerability exists in the garbage collection mechanism of atomic-openshift
ghsa_unreviewed·2022-05-24
CVE-2019-3884 [MEDIUM] CWE-287 GHSA-fpgq-qv2c-6787: A vulnerability exists in the garbage collection mechanism of atomic-openshift
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.
No detection rules found.
No public exploits indexed.
2019-08-01
Published