Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-9946


Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.


Published

2019-04-02T18:30:26.583

Last Modified

2024-11-21T04:52:38.937

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-670

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cncf portmap < 0.7.5 Yes
Application kubernetes kubernetes < 1.11.9 Yes
Application kubernetes kubernetes < 1.12.7 Yes
Application kubernetes kubernetes < 1.13.5 Yes
Application kubernetes kubernetes 1.13.6 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application kubernetes kubernetes 1.14.0 Yes
Application netapp cloud_insights - Yes

References