CVE-2019-15043

CVE-2019-15043

Publicada em · Atualizada em

30Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendepss 63%
probabilidade de exploração
63%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
O que os fabricantes declaram (VEX)

Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.

Afetado
5 produtos (8 componentes)
Red Hat Ceph Storage 2 · Red Hat Ceph Storage 3 · Red Hat Storage 3 · Red Hat OpenShift Container Platform 3.11 · Red Hat OpenShift Container Platform 4
workaround: Block access to the snapshot feature by blocking the /api/snapshots URL via a web application firewall, load balancer, reverse proxy etc. You can also set 'external_enabled' to false to disable external snapshot publish endpoint (default true)…
Corrigido
1 produto (57 componentes)
Red Hat Enterprise Linux AppStream (v. 8)
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
Produtos afetados
n/a · n/a