cve/2019/CVE-2019-3884.md

18 lines
790 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-3884](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3884)
![](https://img.shields.io/static/v1?label=Product&message=atomic-openshift&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%203.6%2C%203.7%2C%203.8%2C%203.9%2C%203.10%2C%203.11%2C%204.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-290&color=brighgreen)
### Description
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon