Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:4151-1

Опубликовано: 21 нояб. 2022
Источник: suse-cvrf

Описание

Security update for cni-plugins

This update for cni-plugins fixes the following issues:

  • CVE-2021-20206: Fixed arbitrary path injection via type field in CNI configuration (bsc#1181961).

Список пакетов

SUSE Linux Enterprise Module for Public Cloud 15
cni-plugins-0.8.6-150000.1.7.1

Описание

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.


Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 15:cni-plugins-0.8.6-150000.1.7.1

Ссылки

Описание

An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.


Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 15:cni-plugins-0.8.6-150000.1.7.1

Ссылки