Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1050-1

Опубликовано: 23 июл. 2020
Источник: suse-cvrf

Описание

Security update for cni-plugins

This update for cni-plugins fixes the following issues:

cni-plugins updated to version 0.8.6

  • CVE-2020-10749: Fixed a potential Man-in-the-Middle attacks in IPv4 clusters by spoofing IPv6 router advertisements (bsc#1172410).

Release notes: https://github.com/containernetworking/plugins/releases/tag/v0.8.6

Список пакетов

openSUSE Leap 15.2
cni-plugins-0.8.6-lp152.2.4.1

Описание

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.


Затронутые продукты
openSUSE Leap 15.2:cni-plugins-0.8.6-lp152.2.4.1

Ссылки