PT-2019-19952 · Linux Foundation+5 · Cni+6

Etienne Champetier

·

Published

2019-03-28

·

Updated

2024-06-15

·

CVE-2019-9946

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions CNI versions 0.7.4 and earlier Kubernetes versions prior to 1.11.9 Kubernetes versions prior to 1.12.7 Kubernetes versions prior to 1.13.5 Kubernetes versions prior to 1.14.0
Description The issue is related to a network firewall misconfiguration in the CNI 'portmap' plugin. This plugin is used to set up HostPorts for CNI and inserts rules at the front of the iptables nat chains, which take precedence over the KUBE-SERVICES chain. As a result, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain.
Recommendations For CNI version 0.7.4, update to version 0.7.5 to resolve the issue. For Kubernetes versions prior to 1.11.9, update to version 1.11.9 or later. For Kubernetes versions prior to 1.12.7, update to version 1.12.7 or later. For Kubernetes versions prior to 1.13.5, update to version 1.13.5 or later. For Kubernetes versions prior to 1.14.0, update to version 1.14.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3403
ALT-PU-2019-1540
CESA-2019_3403
CVE-2019-9946
OPENSUSE-SU-2024:10884-1
RHSA-2019:3403
RHSA-2019_3403
RLSA-2019:3403

Affected Products

Alt Linux
Almalinux
Cni
Centos
Kubernetes
Red Hat
Rocky Linux