{"id":"CVE-2019-3884","details":"A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.","modified":"2026-09-03T08:12:48.836577Z","published":"2019-08-01T14:15:13.190Z","references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3884"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openshift/origin","events":[{"introduced":"c4dd4cf368b6204571faacde702e624b930a5214"},{"last_affected":"b4261e07eda19d9c42aa9d1c748c34f8cba09168"}],"database_specific":{"cpe":["cpe:2.3:a:redhat:openshift:3.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift:3.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift:3.8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift:3.9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift:3.10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift:3.11:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift:4.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.6"},{"last_affected":"3.6"},{"introduced":"3.7"},{"last_affected":"3.7"},{"introduced":"3.8"},{"last_affected":"3.8"},{"introduced":"3.9"},{"last_affected":"3.9"},{"introduced":"3.10"},{"last_affected":"3.10"},{"introduced":"3.11"},{"last_affected":"3.11"},{"introduced":"4.1"},{"last_affected":"4.1"}],"source":"CPE_STRING"}}],"versions":["3.10","3.11","3.6","3.7","3.8","3.9","4.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-3884.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"}]}