CVE-2019-3895

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-3895
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3895.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-3895
Aliases
Related
Published
2019-06-03T19:29:02Z
Modified
2025-01-14T08:02:50.548200Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.

References

Affected packages

Git / github.com/openstack/octavia

Affected ranges

Type
GIT
Repo
https://github.com/openstack/octavia
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.5.0
0.5.1
0.5.2
0.8.0