CVE-2018-5256
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure.
Leer descripción completaMostrar menos
Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.67%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-5256",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-05-18T15:29:00.187",
"references": [
{
"url": "https://coreos.com/blog/tectonic-namespace-information-disclosure-vulnerability-patched",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://coreos.com/tectonic/releases/#1.8.4-tectonic.3",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://coreos.com/blog/tectonic-namespace-information-disclosure-vulnerability-patched",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://coreos.com/tectonic/releases/#1.8.4-tectonic.3",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure. Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges."
},
{
"lang": "es",
"value": "CoreOS Tectonic, en versiones 1.7.x anteriores a la 1.7.9-tectonic.4 y versiones 1.8.x anteriores a la 1.8.4-tectonic.3, monta un proxy directo al clúster kubernetes en /api/kubernetes/, que es accesible sin autenticación en Tectonic y permite que un atacante se conecte directamente al servidor API de kubernetes. Los usuarios no autenticados pueden listar todos los nombres de espacio a través de la consola, lo que resulta en una divulgación de información. La exposición de Tectonic de un endpoint de API no autenticado que contiene información sobre el estado interno del clúster puede proveer a un atacante información que podría ayudar en otros ataques contra el clúster. Por ejemplo, un atacante puede no tener los permisos necesarios para listar todos los espacios de nombre en el clúster, pero podría aprovechar esta vulnerabilidad para enumerar los espacios de nombre y comenzar a comprobar cada uno en busca de políticas de autorización débiles que puedan permitir el escalado de privilegios."
}
],
"lastModified": "2026-06-17T01:59:55.530",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:tectonic:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9A37775-6C22-4B18-AB1D-198F1BE515AE",
"versionEndExcluding": "1.7.9-tectonic.4",
"versionStartIncluding": "1.7.1-tectonic.1"
},
{
"criteria": "cpe:2.3:a:redhat:tectonic:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59EFB0A5-6C9E-45A4-AFA5-A95FD1B8B345",
"versionEndExcluding": "1.8.4-tectonic.3",
"versionStartIncluding": "1.8.4-tectonic.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}