Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8m6-5j3r-8xg4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

EPSS

Процентиль: 70%
0.01414
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.3
redhat
больше 7 лет назад

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

CVSS3: 9.8
nvd
больше 7 лет назад

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

CVSS3: 9.8
debian
больше 7 лет назад

It was found that default configuration of Heketi does not require any ...

CVSS3: 7.3
fstec
больше 7 лет назад

Уязвимость программного средства Heketi, связанная с отсутствием процедуры аутентификации в стандартных настройках, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 70%
0.01414
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306