6.8
CVSSv2

CVE-2016-5392

Published: 05/08/2016 Updated: 12/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 606
Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N

Vulnerability Summary

The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the watch-cache list.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 3.2

Vendor Advisories

The Kubernetes API server contains a watch cache that speeds up performance Due to an input validation error OpenShift Enterprise may return data for other users and projects when queried by a user An attacker with knowledge of other project names could use this vulnerability to view their information ...