Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9946

Опубликовано: 28 мар. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

Отчет

While this issue affects the CNI portmap plugin that is bundled with Kubernetes, it does not affect OpenShift Container Platform as the vulnerable plugin is not included. It also does not affect the version of Kubernetes (embedded in heketi) shipped with Red Hat Gluster Storage 3 as it does not contain the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8container-tools:1.0/containernetworking-pluginsOut of support scope
Red Hat OpenShift Container Platform 3.10atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.4atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.5atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.6atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.7atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.9atomic-openshiftNot affected
Red Hat OpenShift Container Platform 4openshiftNot affected
Red Hat Storage 3heketiNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-841
https://bugzilla.redhat.com/show_bug.cgi?id=1692712kubernetes: Incorrect rule injection in CNI portmap plugin

EPSS

Процентиль: 58%
0.00365
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
nvd
около 6 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
debian
около 6 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Int ...

CVSS3: 7.5
github
около 3 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

oracle-oval
около 6 лет назад

ELSA-2019-4593: kubernetes kubeadm-upgrade kubeadm-ha-setup security update (IMPORTANT)

EPSS

Процентиль: 58%
0.00365
Низкий

6.5 Medium

CVSS3