# CVE-2019-3899

## Summary

- **CVE ID:** CVE-2019-3899
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
- **CWE:** CWE-592
- **Published:** Apr 22, 2019
- **Last Modified:** Mar 14, 2026

## Description

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

## Affected Products

- The Heketi Project — heketi (heketi 6 as shipped with Openshift Container Platform 3.11)

## References

- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3899)
- [CNA](https://access.redhat.com/errata/RHSA-2019:3255)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.41%
- **EPSS Percentile:** 71.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._