Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aloys Augustin

Researcher fromCisco
#45476of 53,635
5.5Total CVSS
Vulnerabilities · 1
PT-2022-18888
5.5
2022-06-06
Calico · Calico · CVE-2022-28224
**Name of the Vulnerable Software and Affected Versions** Calico versions 3.22.1 and below Calico Enterprise versions 3.12.0 and below **Description** The issue is related to insufficient validation in the floating IP feature, which may allow a privileged attacker to set a floating IP annotation to a pod even if the feature is not enabled. This could enable the attacker to intercept and reroute traffic to their compromised pod. **Recommendations** For Calico versions 3.22.1 and below, consider disabling the floating IP feature until a patch is available. For Calico Enterprise versions 3.12.0 and below, restrict access to the floating IP annotation to minimize the risk of exploitation.