openshift-ansible: dockergc service account incorrectly associated with namespace during upgrade
Published Jan 7, 2020
8.8
HIGHCVSS 3.1
EPSS 1.07%
Description
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
Affected products
- Vendor n/a Product Openshift-Ansible Defaultn/a
- Version 3.xStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Openshift-Ansible | n/a |
|
- 3.10
- 3.11
No data.
Red Hat OpenShift Container Platform 3.11
openshift-ansible-0:3.11.146-1.git.0.fcedb45.el7
Fixed · RHSA-2019:2818
Red Hat OpenShift Container Platform 3.10
openshift-ansible
Affected
Red Hat OpenShift Container Platform 3.9
openshift-ansible
Not affected
Red Hat OpenShift Container Platform 4
openshift-ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | openshift-ansible-0:3.11.146-1.git.0.fcedb45.el7 | Fixed | RHSA-2019:2818 |
| Red Hat OpenShift Container Platform 3.10 | openshift-ansible | Affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | openshift-ansible | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift-ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
If an upgrade was run with the openshift_crio_enable_docker_gc ansible variable set to 'False' the cluster won't be affected. The default for the variable was set to 'True' before openshift-ansible-3.11.0-0.28.0, and after 3.10.x. See https://github.com/openshift/openshift-ansible/commit/bf5fbea4138f27313c5e4dcd683821975db8e443
Red Hat mitigation
Make sure your kubeconfig (~/.kube/config) is using the 'default' context when executing, or re-executing a cluster upgrade or install using the ansible playbooks.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.07% (0.01074) | 63.76th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.05% (0.01053) | 62.87th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.09% (0.00091) | 39.55th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.09% (0.00091) | 38.24th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00085) | 34.54th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.84% (0.01840) | 47.83th | v1 |
| Jan 6, 2022 | 1.84% (0.01840) | 47.32th | v1 |
| Jan 5, 2022 | 0.42% (0.00416) | 26.65th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (5)
- https://access.redhat.com/security/cve/CVE-2019-14819 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1746238 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14819 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14819
- https://www.cve.org/CVERecord?id=CVE-2019-14819
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-14819 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1746238 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14819 | x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14819 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-14819 |
Change history (0)
No recorded changes yet.