CVE-2019-9946
published 2019-04-02CVE-2019-9946: Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
3.12%
86.4th percentile
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cncf | portmap | < 0.7.5 | 0.7.5 |
| debian | golang-github-containernetworking-plugins | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| debian | kubernetes | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| debian | singularity-container | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| kubernetes | kubernetes | < 1.11.9 | 1.11.9 |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 1.12.0 < 1.12.7 | 1.12.7 |
| kubernetes | kubernetes | >= 1.13.0 < 1.13.5 | 1.13.5 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6g96-g4m6-hw69: Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0
ghsa_unreviewed·2022-05-13
CVE-2019-9946 [HIGH] CWE-670 GHSA-6g96-g4m6-hw69: Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
OSV
CVE-2019-9946: Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0
osv·2019-04-02·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946: Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
Red Hat
kubernetes: Incorrect rule injection in CNI portmap plugin
vendor_redhat·2019-03-28·CVSS 7.5
CVE-2019-9946 [HIGH] CWE-841 kubernetes: Incorrect rule injection in CNI portmap plugin
kubernetes: Incorrect rule injection in CNI portmap plugin
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
Statement: While this issue affects the CNI portmap plugin that is bundled with Kubernetes, it does not affect OpenShift Container Platform as the vulnerable
Debian
CVE-2019-9946: golang-github-containernetworking-plugins - Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0....
vendor_debian·2019·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946: golang-github-containernetworking-plugins - Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0....
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
HackerOne
IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
hackerone·2021-11-07·CVSS 8.1
CVE-2019-9946 [HIGH] IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
This bug report mostly concerns the default CNI plugins (https://github.com/containernetworking/plugins) but I believe affects many K8S clusters.
Because the CNI team still doesn’t provide an explicit way to report security bugs, I hope the K8S security team doesn’t mind doing the coordination job again as was done for CVE-2019-9946.
I understand this is out of scope for this bounty, and I understand if you want to close this report and prefer that I resend it via email to [email protected] or other.
## Summary:
In many K8S network configurations the container network interface is a virtual ethernet link going to the host (veth interface). In this configuration, an attacker able to run a process as r
Bugzilla
CVE-2019-9946 containernetworking-plugins: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
bugzilla·2019-05-31·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946 containernetworking-plugins: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
CVE-2019-9946 containernetworking-plugins: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2019-9946 containernetworking-cni: kubernetes: Incorrect rule injection in CNI portmap plugin [epel-7]
bugzilla·2019-05-30·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946 containernetworking-cni: kubernetes: Incorrect rule injection in CNI portmap plugin [epel-7]
CVE-2019-9946 containernetworking-cni: kubernetes: Incorrect rule injection in CNI portmap plugin [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the follow
Bugzilla
CVE-2019-9946 kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
bugzilla·2019-03-29·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946 kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
CVE-2019-9946 kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2019-9946 kubernetes:openshift-3.10/origin: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-29]
bugzilla·2019-03-29·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946 kubernetes:openshift-3.10/origin: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-29]
CVE-2019-9946 kubernetes:openshift-3.10/origin: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Bugzilla
CVE-2019-9946 kubernetes:1.1/kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-29]
bugzilla·2019-03-29·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946 kubernetes:1.1/kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-29]
CVE-2019-9946 kubernetes:1.1/kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following
Bugzilla
CVE-2019-9946 origin: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
bugzilla·2019-03-29·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946 origin: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
CVE-2019-9946 origin: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2019-9946 kubernetes: Incorrect rule injection in CNI portmap plugin
bugzilla·2019-03-26·CVSS 7.5
CVE-2019-9946 [HIGH] CVE-2019-9946 kubernetes: Incorrect rule injection in CNI portmap plugin
CVE-2019-9946 kubernetes: Incorrect rule injection in CNI portmap plugin
It was found that the 'portmap' plugin, used to setup HostPorts for CNI, would insert rules at the front of the iptables nat chains; which would take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain.
Upstream issue:
https://github.com/containernetworking/plugins/pull/269
Upstream patch:
https://github.com/containernetworking/plugins/pull/269/commits/f8fcb3525fc5c4a2bdc1a791b5c7b46a29ef4f04
Discussion:
Upstream Patch:
https://github.com/kubernetes/kubernetes/pull/75455
https://github.com/containernetworking/plugins/pull/269
---
External Ref
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
arxiv_fulltext·2024-07-31
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Raveen Kanishka Jayalath*
University of Adelaide, Australia
[email protected]
Hussain Ahmad* *Authors contributed equally to this work. Corresponding author.
University of Adelaide, Australia
[email protected]
Diksha Goel
CSIRO's Data61, Australia
[email protected]
3cmMuhammad Shuja Syed
3cmSLB, USA
[email protected]
Faheem Ullah
University of Adelaide, Australia
[email protected]
plain
## Abstract
Microservice architectures are revolutionizing both small businesses and large corporations, igniting a new era of innovation with their exceptional advantages in maintainability, reusability, and scalability. However, these benefits come w
https://access.redhat.com/errata/RHBA-2019:0862https://github.com/containernetworking/plugins/pull/269#issuecomment-477683272https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCN66VYB3XS76SYH567SO7N3I254JOCT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGOOWAELGH3F7OXRBPH3HCNZELNLXYTW/https://security.netapp.com/advisory/ntap-20190416-0002/https://access.redhat.com/errata/RHBA-2019:0862https://github.com/containernetworking/plugins/pull/269#issuecomment-477683272https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCN66VYB3XS76SYH567SO7N3I254JOCT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGOOWAELGH3F7OXRBPH3HCNZELNLXYTW/https://security.netapp.com/advisory/ntap-20190416-0002/
2019-04-02
Published