Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-14891


A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.


Published

2019-11-25T11:15:11.430

Last Modified

2024-11-21T04:27:37.410

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-460
  • Type: Primary
    CWE-754

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application kubernetes cri-o < 1.16.1 Yes
Operating System fedoraproject fedora - Yes
Application redhat openshift_container_platform 3.11 Yes
Application redhat openshift_container_platform 4.1 Yes
Application redhat openshift_container_platform 4.2 Yes

References