CVE-2019-10225
MEDIUMOpenShift Container Platform 4.2 - Info Disclosure
Title source: llmDescription
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.
Scores
CVSS v3
6.3
EPSS
0.0015
EPSS Percentile
35.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-522
Status
published
Affected Products (3)
redhat/openshift
redhat/openshift_container_platform
redhat/openshift_container_platform
Timeline
Published
Mar 19, 2021
Tracked Since
Feb 18, 2026