VYPR
High severity8.0NVD Advisory· Published Jun 3, 2019· Updated Jun 17, 2026

CVE-2019-3895

CVE-2019-3895

Description

An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
octaviaPyPI
< 0.9.00.9.0

Affected products

4

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.