CVE-2019-3884

3.6LOW

Key Information:

Vendor
Red Hat
Vendor
CVE Published:
1 August 2019

Summary

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

Affected Version(s)

atomic-openshift 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 4.1

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.