Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0567

Опубликовано: 20 апр. 2022
Источник: nvd
CVSS3: 9.1
CVSS2: 6.5
EPSS Низкий

Описание

A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:*
Версия до 4.7.47 (исключая)
cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:*
Версия от 4.8.0 (включая) до 4.8.36 (исключая)
cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:*
Версия от 4.9.0 (включая) до 4.9.27 (исключая)
cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:*
Версия от 4.10.0 (включая) до 4.10.8 (исключая)

EPSS

Процентиль: 61%
0.01025
Низкий

9.1 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.2
redhat
больше 4 лет назад

A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.

CVSS3: 9.1
github
больше 4 лет назад

A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.

CVSS3: 9.1
fstec
больше 4 лет назад

Уязвимость сетевого провайдер для Kubernetes основанный на OVN (Open Virtual Network) OVN-Kubernetes, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю раскрыть защищаемую информацию или оказать другое воздействие

EPSS

Процентиль: 61%
0.01025
Низкий

9.1 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo