Vulnerabilities > CVE-2019-3682 - Exposure of Resource to Wrong Sphere vulnerability in Suse Caas Platform 3.0

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
suse
CWE-668

Summary

The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.

Vulnerable Configurations

Part Description Count
Application
Suse
1

Common Weakness Enumeration (CWE)