CVE-2019-3899: Heketi Project Heketi

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

Affected products

  • Heketi Project Heketi: affected versions not specified
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2019-04-22. Last modified 2026-06-17.