Vulnerabilities > CVE-2019-3682 - Exposure of Resource to Wrong Sphere vulnerability in Suse Caas Platform 3.0

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
suse
CWE-668

Summary

The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.

Vulnerable Configurations

Part Description Count
Application
Suse
1

Common Weakness Enumeration (CWE)