Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10749

Опубликовано: 03 июн. 2020
Источник: nvd
CVSS3: 6
CVSS2: 6
EPSS Низкий

Описание

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linuxfoundation:cni_network_plugins:*:*:*:*:*:*:*:*
Версия до 0.8.6 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.036
Низкий

6 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-300
NVD-CWE-Other

Связанные уязвимости

CVSS3: 6
ubuntu
около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
redhat
около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
debian
около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugi ...

suse-cvrf
почти 5 лет назад

Security update for cni-plugins

suse-cvrf
почти 5 лет назад

Security update for cni-plugins

EPSS

Процентиль: 87%
0.036
Низкий

6 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-300
NVD-CWE-Other