CVE-2019-4119

Severity
5.3MEDIUM
EPSS
0.3%
top 50.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateMay 24

Description

IBM Cloud Private Kubernetes API server 2.1.0, 3.1.0, 3.1.1, and 3.1.2 can be used as an HTTP proxy to not only cluster internal but also external target IP addresses. IBM X-Force ID: 158145.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDibm/cloud_private2.1.0.02.1.0.3+3
CVEListV5ibm/cloud_private4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rv59-69qx-jg7m: IBM Cloud Private Kubernetes API server 22022-05-24
CVEList
CVE-2019-4119: IBM Cloud Private Kubernetes API server 22019-05-17
CVE-2019-4119 (MEDIUM CVSS 5.3) | IBM Cloud Private Kubernetes API se | cvebase.io