CVE-2019-3895
openstack-tripleo-common: Allows running new amphorae based on arbitrary images
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
Se descubrió un fallo de control de acceso en el servicio de Octavia cuando la plataforma en la nube se implementó con el Director de la plataforma de Red Hat OpenStack. Un atacante podría hacer que se ejecuten nuevas ánforas en función de cualquier imagen arbitraria. Esto significaba que un atacante remoto podía cargar una nueva imagen de ánforas y, si se le pedía que generar nuevas ánforas, Octavia recogería la imagen comprometida.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-06-03 CVE Published
- 2024-08-04 CVE Updated
- 2024-10-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3895 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:1683 | 2021-08-04 | |
https://access.redhat.com/errata/RHSA-2019:1742 | 2021-08-04 | |
https://access.redhat.com/security/cve/CVE-2019-3895 | 2019-07-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1694608 | 2019-07-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Octavia Search vendor "Openstack" for product "Octavia" | < 0.9.0 Search vendor "Openstack" for product "Octavia" and version " < 0.9.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 12 Search vendor "Redhat" for product "Openstack" and version "12" | - |
Affected
|