PT-2022-19433 · Cilium · Cilium

Joestringer

·

Published

2022-05-20

·

Updated

2024-08-21

·

CVE-2022-29179

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cilium versions prior to 1.9.16 Cilium versions prior to 1.10.11 Cilium versions prior to 1.11.5
Description Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. If an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium's Kubernetes service account. The attacker can leverage Cilium's Kubernetes service account to gain access to cluster privileges that are more permissive than what is minimally required to operate Cilium, including modifying and deleting Pod and Node resources.
Recommendations For versions prior to 1.9.16, update to version 1.9.16 or later. For versions prior to 1.10.11, update to version 1.10.11 or later. For versions prior to 1.11.5, update to version 1.11.5 or later. As a temporary workaround, consider restricting access to Cilium's Kubernetes service account until a patch is applied.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CILIUM-2022-29179
BIT-CILIUM-OPERATOR-2022-29179
BIT-CILIUM-PROXY-2022-29179
BIT-HUBBLE-2022-29179
BIT-HUBBLE-RELAY-2022-29179
BIT-HUBBLE-UI-2022-29179
BIT-HUBBLE-UI-BACKEND-2022-29179
CVE-2022-29179
GHSA-FMRF-GVJP-5J5G
GO-2022-0458

Affected Products

Cilium