Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3899

Опубликовано: 18 апр. 2019
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

It was found that the default configuration of Heketi does not require any authentication, potentially exposing the Heketi server API to be misused. An unauthenticated attacker could connect remotely to Heketi Server and run arbitrary commands supported by Heketi Server API via Heketi CLI.

Меры по смягчению последствий

After installation of Heketi

  1. configure user and admin key in /etc/heketi/heketi.json file ... { "_port_comment": "Heketi Server Port Number", "port": "8080", "_use_auth": "Enable JWT authorization. Please enable for deployment", "use_auth": true, "_jwt": "Private keys for access", "jwt": { "_admin": "Admin has access to all APIs", "admin": { "key": "My Secret" }, "_user": "User only has access to /volumes endpoint", "user": { "key": "My Secret" } }, ...
  2. restart heketi server

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1701091heketi: heketi can be installed using insecure defaults

EPSS

Процентиль: 60%
0.00395
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 7 лет назад

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

CVSS3: 9.8
debian
почти 7 лет назад

It was found that default configuration of Heketi does not require any ...

CVSS3: 9.8
github
больше 3 лет назад

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

CVSS3: 7.3
fstec
почти 7 лет назад

Уязвимость программного средства Heketi, связанная с отсутствием процедуры аутентификации в стандартных настройках, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 60%
0.00395
Низкий

7.3 High

CVSS3