CVE-2019-15043

CVE-2019-15043

Publicada el · Actualizada el

30Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 63%
probabilidad de explotación
63%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
5 productos (8 componentes)
Red Hat Ceph Storage 2 · Red Hat Ceph Storage 3 · Red Hat Storage 3 · Red Hat OpenShift Container Platform 3.11 · Red Hat OpenShift Container Platform 4
workaround: Block access to the snapshot feature by blocking the /api/snapshots URL via a web application firewall, load balancer, reverse proxy etc. You can also set 'external_enabled' to false to disable external snapshot publish endpoint (default true)…
Corregido
1 producto (57 componentes)
Red Hat Enterprise Linux AppStream (v. 8)
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
Productos afectados
n/a · n/a