Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8m6-5j3r-8xg4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

EPSS

Процентиль: 60%
0.00395
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.3
redhat
почти 7 лет назад

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

CVSS3: 9.8
nvd
почти 7 лет назад

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

CVSS3: 9.8
debian
почти 7 лет назад

It was found that default configuration of Heketi does not require any ...

CVSS3: 7.3
fstec
почти 7 лет назад

Уязвимость программного средства Heketi, связанная с отсутствием процедуры аутентификации в стандартных настройках, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 60%
0.00395
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306