PT-2022-2955 · Unknown · Ovn Kubernetes
Sam Fowler
·
Published
2022-04-20
·
Updated
2022-05-04
·
CVE-2022-0567
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ovn-kubernetes (affected versions not specified)
Description
A flaw in ovn-kubernetes allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster. This results in information disclosure and other attacks on pods that should not be reachable. The issue is related to insufficient input validation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ovn Kubernetes