High severity8.8NVD Advisory· Published Jan 7, 2020· Updated Jun 17, 2026
CVE-2019-14819
CVE-2019-14819
Description
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- (no CPE)range: 3.x
Patches
Vulnerability mechanics
References
1- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.