CVE-2019-3682

Severity
7.8HIGH
EPSS
0.1%
top 66.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateMay 24

Description

The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages2 packages

CVEListV5suse/suse_caas_platform_3.0docker-kubic17.09.1_ce-7.6.1

🔴Vulnerability Details

2
GHSA
GHSA-jh4h-8jgf-wfh2: The docker-kubic package in SUSE CaaS Platform 32022-05-24
CVEList
Insecure API port exposed to all Master Node guest containers2020-01-17
CVE-2019-3682 (HIGH CVSS 7.8) | The docker-kubic package in SUSE Ca | cvebase.io