A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.
2022-04-20T16:15:08.310
2024-11-21T06:38:56.037
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ovn | ovn-kubernetes | < 4.7.47 | Yes |
Application | ovn | ovn-kubernetes | < 4.8.36 | Yes |
Application | ovn | ovn-kubernetes | < 4.9.27 | Yes |
Application | ovn | ovn-kubernetes | < 4.10.8 | Yes |