CVE-2020-10749
published 2020-06-03CVE-2020-10749: A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to…
PriorityP433medium6CVSS 3.1
AVNACHPRLUINSCCLILAL
EPSS
2.43%
82.4th percentile
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-containernetworking-plugins | < golang-github-containernetworking-plugins 0.8.6-1 (bookworm) | golang-github-containernetworking-plugins 0.8.6-1 (bookworm) |
| fedoraproject | fedora | — | — |
| github.com | containernetworking_plugins | >= 0 < 0.8.6 | 0.8.6 |
| linuxfoundation | cni_network_plugins | < 0.8.6 | 0.8.6 |
| red_hat | containernetworking_plugins | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters
vendor_redhat·2020-06-01·CVSS 6.0
CVE-2020-10749 [MEDIUM] CWE-300 containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters
containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
A vulnerability was found in affected container networking implementations that allow malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending “rogue” IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious co
Debian
CVE-2020-10749: golang-github-containernetworking-plugins - A vulnerability was found in all versions of containernetworking/plugins before ...
vendor_debian·2020·CVSS 6.0
CVE-2020-10749 [MEDIUM] CVE-2020-10749: golang-github-containernetworking-plugins - A vulnerability was found in all versions of containernetworking/plugins before ...
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
Scope: local
bookworm: resolved (fixed in 0.8.6-1)
bullseye: resolved (fixed in 0.8.6-1)
forky: resolved (fixed in 0.8.6-1)
sid: resolved (fixed in 0.8.6-1)
trixie: resolved (fixed in 0.8.6-1)
OSV
containernetworking/plugins vulnerable to MitM attacks in github.com/containernetworking/plugins
osv·2024-08-20
CVE-2020-10749 containernetworking/plugins vulnerable to MitM attacks in github.com/containernetworking/plugins
containernetworking/plugins vulnerable to MitM attacks in github.com/containernetworking/plugins
containernetworking/plugins vulnerable to MitM attacks in github.com/containernetworking/plugins
OSV
containernetworking/plugins vulnerable to MitM attacks
osv·2022-05-24
CVE-2020-10749 [MEDIUM] containernetworking/plugins vulnerable to MitM attacks
containernetworking/plugins vulnerable to MitM attacks
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
GHSA
containernetworking/plugins vulnerable to MitM attacks
ghsa·2022-05-24
CVE-2020-10749 [MEDIUM] CWE-300 containernetworking/plugins vulnerable to MitM attacks
containernetworking/plugins vulnerable to MitM attacks
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
OSV
CVE-2020-10749: A vulnerability was found in all versions of containernetworking/plugins before version 0
osv·2020-06-03·CVSS 6.0
CVE-2020-10749 [MEDIUM] CVE-2020-10749: A vulnerability was found in all versions of containernetworking/plugins before version 0
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10749 containernetworking-plugins: containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters [fedora-all]
bugzilla·2020-06-01·CVSS 6.0
CVE-2020-10749 [MEDIUM] CVE-2020-10749 containernetworking-plugins: containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters [fedora-all]
CVE-2020-10749 containernetworking-plugins: containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2020-10749 golang-github-containernetworking-plugins: containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters [fedora-all]
bugzilla·2020-06-01·CVSS 6.0
CVE-2020-10749 [MEDIUM] CVE-2020-10749 golang-github-containernetworking-plugins: containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters [fedora-all]
CVE-2020-10749 golang-github-containernetworking-plugins: containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chang
Bugzilla
CVE-2020-10749 containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters
bugzilla·2020-05-08·CVSS 6.0
CVE-2020-10749 [MEDIUM] CVE-2020-10749 containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters
CVE-2020-10749 containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters
CNI network plugins create network bridges that IPv6 router advertisements by default. An attacker able to execute code in a container could exploit this to spoof rouge IPv6 router advertisements in IPv4 clusters to perform a MitM attack against the host network or another container on the same host.
Discussion:
*** Bug 1833219 has been marked as a duplicate of this bug. ***
---
*** Bug 1833215 has been marked as a duplicate of this bug. ***
---
Upstream Fix:
https://github.com/containernetworking/plugins/pull/484
---
Acknowledgments:
Name: the Kubernetes Product Security Committee
Upstream: Etienne Champetier
---
Mitigation:
Prevent untrusted, non-privileged contain
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00065.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10749https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DV3HCDZYUTPPVDUMTZXDKK6IUO3JMGJC/http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00065.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10749https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DV3HCDZYUTPPVDUMTZXDKK6IUO3JMGJC/
2020-06-03
Published