Lucene search

K
nvd[email protected]NVD:CVE-2019-14891
HistoryNov 25, 2019 - 11:15 a.m.

CVE-2019-14891

2019-11-2511:15:11
CWE-460
CWE-754
web.nvd.nist.gov
4

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS3

5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

31.4%

A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.

Affected configurations

Nvd
Node
kubernetescri-oRange<1.16.1
Node
fedoraprojectfedoraMatch-
Node
redhatopenshift_container_platformMatch3.11
OR
redhatopenshift_container_platformMatch4.1
OR
redhatopenshift_container_platformMatch4.2
VendorProductVersionCPE
kubernetescri-o*cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*
fedoraprojectfedora-cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*
redhatopenshift_container_platform3.11cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
redhatopenshift_container_platform4.1cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
redhatopenshift_container_platform4.2cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS3

5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

31.4%