CVE-2020-14336
published 2021-06-02CVE-2020-14336: A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.93%
56.6th percentile
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system availability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qr9q-882c-gv4j: A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets
ghsa_unreviewed·2022-05-24
CVE-2020-14336 [MEDIUM] CWE-770 GHSA-qr9q-882c-gv4j: A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system availability.
Red Hat
openshift: restricted SCC allows pods to craft custom network packets
vendor_redhat·2020-07-13·CVSS 6.5
CVE-2020-14336 [MEDIUM] CWE-770 openshift: restricted SCC allows pods to craft custom network packets
openshift: restricted SCC allows pods to craft custom network packets
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system availability.
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system availability.
Statement: By default, the OpenShift Container Platform uses the OpenSh
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4]
bugzilla·2020-09-01·CVSS 6.5
CVE-2020-14336 [MEDIUM] CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4]
CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4]
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory (Moderate: OpenShift Container Platform 4.6.1 image security update), and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHSA-2020:4298
Bugzilla
CVE-2020-14336 openshift: restricted SCC allows pods to craft custom network packets
bugzilla·2020-07-21·CVSS 6.5
CVE-2020-14336 [MEDIUM] CVE-2020-14336 openshift: restricted SCC allows pods to craft custom network packets
CVE-2020-14336 openshift: restricted SCC allows pods to craft custom network packets
The Restricted Security Context Constraints (SCC) allows pods to craft custom network packets. An attacker can use this flaw to cause a denial of service attack on an OpenShift Container Platform cluster if they have the ability to deploy pods.
Discussion:
Acknowledgments:
Name: Yuval Kashtan (Red Hat)
---
While removing CAP_NET_RAW from the default capability set is a great change, I think it is better tracked as security hardening issue rather than a CVE. It's a stretch IMO to consider the inclusion of this capability a flaw on it's own, considering that other projects also include it by default, e.g.
Docker: https://docs.docker.com/engine/reference/run/#runtime-privilege-and-linux-capabilities
li
Bugzilla
CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4]
bugzilla·2020-07-13·CVSS 6.5
CVE-2020-14336 [MEDIUM] CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4]
CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4]
https://openshift-release.apps.ci.l2s4.p1.openshiftapps.com/releasestream/4.5.0-0.nightly/release/4.5.0-0.nightly-2020-10-16-165114 brings in the new MCD RPM with a machine-os-content RHCOS bump to 45.82.202010161329-0. I'm a bit fuzzy on whether it's the RPM or a container image that's used for in-cluster MCDs, but probably worth using 4.5.0-0.nightly-2020-10-16-165114 or later for verification just in case ;).
Discussion:
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory (Low: OpenShift Container Platform 4.5.16 security update), an
2021-06-02
Published