Vulnerabilities > Redhat > Tectonic > High

DATE CVE VULNERABILITY TITLE RISK
2018-05-18 CVE-2018-5256 Information Exposure vulnerability in Redhat Tectonic
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server.
network
low complexity
redhat CWE-200
7.5