CVE-2019-3682: Insecure API port exposed to all Master Node guest containers
Published Jan 17, 2020
·Updated
The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.
Affected Software
1 affected component
SUSE CaaS Platform=3.0
Event History
Jan 17, 2020
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-3682.
2
What is the severity of CVE-2019-3682?
The severity of CVE-2019-3682 is high with a severity value of 7.8.
3
What software is affected by CVE-2019-3682?
SUSE CaaS Platform 3.0 is affected by CVE-2019-3682.
4
What is the description of CVE-2019-3682?
CVE-2019-3682 is a vulnerability in the docker-kubic package in SUSE CaaS Platform 3.0 that provides access to an insecure API locally on the Kubernetes master node.
5
Is there a fix available for CVE-2019-3682?
Yes, a fix for CVE-2019-3682 is available. Please refer to the SUSE advisory for more information.