CVE-2020-10749
Vulnerability Summary
Timeline
Description
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
CVSS Metrics
- v3.1•MEDIUM•Score: 6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
- v2.0•MEDIUM•Score: 6AV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 2.43%• Percentile: 83%
Techniques & Countermeasures
- CWE-300•Channel Accessible by Non-Endpoint
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
Affected Systems
- chainguard•cni-plugins-fips
< 0
- chainguard•cni-plugins-fips-bandwidth
< 0
- chainguard•cni-plugins-fips-bandwidth-compat
< 0
- chainguard•cni-plugins-fips-bridge
< 0
- chainguard•cni-plugins-fips-bridge-compat
< 0
- chainguard•cni-plugins-fips-dhcp
< 0
- chainguard•cni-plugins-fips-dhcp-compat
< 0
- chainguard•cni-plugins-fips-dummy
< 0
- chainguard•cni-plugins-fips-dummy-compat
< 0
- chainguard•cni-plugins-fips-firewall
< 0
- chainguard•cni-plugins-fips-firewall-compat
< 0
- chainguard•cni-plugins-fips-host-device
< 0
- chainguard•cni-plugins-fips-host-device-compat
< 0
- chainguard•cni-plugins-fips-host-local
< 0
- chainguard•cni-plugins-fips-host-local-compat
< 0
- chainguard•cni-plugins-fips-ipam
< 0
- chainguard•cni-plugins-fips-ipvlan
< 0
- chainguard•cni-plugins-fips-ipvlan-compat
< 0
- chainguard•cni-plugins-fips-loopback
< 0
- chainguard•cni-plugins-fips-loopback-compat
< 0
- chainguard•cni-plugins-fips-macvlan
< 0
- chainguard•cni-plugins-fips-macvlan-compat
< 0
- chainguard•cni-plugins-fips-main
< 0
- chainguard•cni-plugins-fips-meta
< 0
- chainguard•cni-plugins-fips-portmap
< 0
- chainguard•cni-plugins-fips-portmap-compat
< 0
- chainguard•cni-plugins-fips-ptp
< 0
- chainguard•cni-plugins-fips-ptp-compat
< 0
- chainguard•cni-plugins-fips-sbr
< 0
- chainguard•cni-plugins-fips-sbr-compat
< 0
- chainguard•cni-plugins-fips-static
< 0
- chainguard•cni-plugins-fips-static-compat
< 0
- chainguard•cni-plugins-fips-tuning
< 0
- chainguard•cni-plugins-fips-tuning-compat
< 0
- chainguard•cni-plugins-fips-vlan
< 0
- chainguard•cni-plugins-fips-vlan-compat
< 0
- debian•golang-github-containernetworking-plugins
< 0.8.6-1 | < 0.8.6-1 | < 0.8.6-1 | < 0.8.6-1
- fedoraproject•fedora
32
- github.com/containernetworking•plugins
< 0.8.6
- linuxfoundation•cni_network_plugins
< 0.8.6
- red hat•containernetworking/plugins
all containernetworking/plugins versions before version 0.8.6
- redhat•enterprise_linux
7.0 | 8.0
- redhat•openshift_container_platform
4.0
- redhat•containernetworking-plugins
< 0:0.8.6-1.rhaos4.4.el7 | < 0:0.8.6-1.rhaos4.4.el8 | < 0:0.8.6-1.rhaos4.3.el7 | < 0:0.8.6-1.rhaos4.3.el8 | < 0:0.8.6-1.rhaos4.2.el7 | < 0:0.8.6-1.rhaos4.2.el8 | < 0:0.8.3-3.el7_8
- redhat•containernetworking-plugins-debuginfo
< 0:0.8.6-1.rhaos4.4.el7 | < 0:0.8.6-1.rhaos4.4.el8 | < 0:0.8.6-1.rhaos4.3.el7 | < 0:0.8.6-1.rhaos4.3.el8 | < 0:0.8.6-1.rhaos4.2.el7 | < 0:0.8.6-1.rhaos4.2.el8 | < 0:0.8.3-3.el7_8
- redhat•containernetworking-plugins-debugsource
< 0:0.8.6-1.rhaos4.4.el8 | < 0:0.8.6-1.rhaos4.3.el8 | < 0:0.8.6-1.rhaos4.2.el8
References (24)
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10749
- https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00063.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00065.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DV3HCDZYUTPPVDUMTZXDKK6IUO3JMGJC/
- https://nvd.nist.gov/vuln/detail/CVE-2020-10749
- https://github.com/containernetworking/plugins
- https://github.com/containernetworking/plugins/releases/tag/v0.8.6
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/BMb_6ICCfp8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DV3HCDZYUTPPVDUMTZXDKK6IUO3JMGJC
- https://github.com/advisories/GHSA-fx6x-h9g4-56f8
- https://access.redhat.com/errata/RHSA-2020:2403
- https://access.redhat.com/security/updates/classification/#moderate
- https://bugzilla.redhat.com/show_bug.cgi?id=1833220
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2403.json
- https://access.redhat.com/security/cve/CVE-2020-10749
- https://www.cve.org/CVERecord?id=CVE-2020-10749
- https://access.redhat.com/errata/RHSA-2020:2443
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2443.json
- https://access.redhat.com/errata/RHSA-2020:2592
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2592.json
- https://access.redhat.com/errata/RHSA-2020:2684
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2684.json
- https://security-tracker.debian.org/tracker/CVE-2020-10749