CVE-2019-3899
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.40%
- CWE
- CWE-592
- Published
- 2019-04-22
- Last modified
- 2026-03-14
Affected products
- The Heketi Project heketi
Weakness type
Related vulnerabilities
- CVE-2026-43512 — Apache Tomcat: Digest authenticator will authenticate any unknown user
- CVE-2023-30971 — Gaia unauthenticated endpoints
- CVE-2019-14843 — A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests...
- CVE-2019-14910 — A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation...
- CVE-2019-14909 — A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP...
- CVE-2019-10201 — It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message...
- CVE-2019-10198 — An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously,...
- CVE-2014-5432 — Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module...