A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
2020-06-03T14:15:12.470
2024-11-21T04:55:59.307
Modified
CVSSv3.1: 6.0 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxfoundation | cni_network_plugins | < 0.8.6 | Yes |
Application | redhat | openshift_container_platform | 4.0 | Yes |
Operating System | fedoraproject | fedora | 32 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |