PT-2021-7911 · Unknown+2 · Containernetworking/Cni+2

Pedro Sampaio

·

Published

2021-01-19

·

Updated

2024-06-15

·

CVE-2021-20206

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions containernetworking/cni versions prior to 0.8.1
Description The issue is related to an improper limitation of path name flaw in the Container Network Interface (CNI) that can be exploited by an attacker to execute other existing binaries on the system, potentially affecting the confidentiality, integrity, and availability of protected information. This can be achieved by using special elements such as "../" separators when specifying the plugin to load in the 'type' field in the network configuration. The vulnerability allows attackers to reference binaries elsewhere on the system, including executing commands like 'reboot'.
Recommendations For containernetworking/cni versions prior to 0.8.1, update to version 0.8.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the 'type' field in the network configuration to prevent the execution of arbitrary binaries until a patch is applied. Avoid using special elements such as "../" separators when specifying plugins to load.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-44838
BDU:2023-05301
CVE-2021-20206
GHSA-XJQR-G762-PXWP
GO-2022-0230
MGASA-2023-0213
OPENSUSE-SU-2022:0770-1
OPENSUSE-SU-2022_0770-1
OPENSUSE-SU-2022_3655-1
OPENSUSE-SU-2022_3766-1
OPENSUSE-SU-2022_4592-1
OPENSUSE-SU-2022_4593-1
OPENSUSE-SU-2023_0187-1
OPENSUSE-SU-2024:10666-1
OPENSUSE-SU-2024:12371-1
OPENSUSE-SU-2024:12512-1
OPENSUSE-SU-2024:12513-1
SNYK-GOLANG-GITHUBCOMCONTAINERNETWORKINGCNIPKGINVOKE-1070549
SUSE-SU-2022:0770-1
SUSE-SU-2022:3480-1
SUSE-SU-2022:3655-1
SUSE-SU-2022:3766-1
SUSE-SU-2022:4150-1
SUSE-SU-2022:4151-1
SUSE-SU-2022:4592-1
SUSE-SU-2022:4593-1
SUSE-SU-2022_4150-1
SUSE-SU-2022_4592-1
SUSE-SU-2022_4593-1
SUSE-SU-2023:0187-1
SUSE-SU-2023:0326-1

Affected Products

Astra Linux
Suse
Containernetworking/Cni