CVE-2019-9946 — Always-Incorrect Control Flow Implementation in Portmap
Severity
7.5HIGHNVD
EPSS
0.5%
top 32.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateJul 31
Description
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. Th…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages6 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
2📄Research Papers
1💬Community
8HackerOne
▶
Bugzilla▶
CVE-2019-9946 containernetworking-plugins: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]↗2019-05-31
Bugzilla▶
CVE-2019-9946 containernetworking-cni: kubernetes: Incorrect rule injection in CNI portmap plugin [epel-7]↗2019-05-30
Bugzilla
▶
Bugzilla▶
CVE-2019-9946 kubernetes:openshift-3.10/origin: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-29]↗2019-03-29