VYPR
High severity8.8NVD Advisory· Published Jan 7, 2020· Updated Jun 17, 2026

CVE-2019-14819

CVE-2019-14819

Description

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
    • (no CPE)range: 3.x
  • Red Hat/Openshiftcpe-rescue
    Range: 3.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.