Vulnerability Name: | CVE-2019-9946 (CCN-158803) |
Assigned: | 2019-03-28 |
Published: | 2019-03-28 |
Updated: | 2020-08-24 |
Summary: | Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0. |
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): High Availibility (A): None | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None | 6.5 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L) 5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-670 CWE-841
|
Vulnerability Consequences: | Bypass Security |
References: | Source: MITRE Type: CNA CVE-2019-9946
Source: CCN Type: IBM Security Bulletin 878460 (Cloud Private) Multiple Security Vulnerabilities affect IBM Cloud Private Kubernetes
Source: CCN Type: IBM Security Bulletin 879585 (Cloud Kubernetes Service) IBM Cloud Kubernetes Service is affected by a CNI security vulnerability
Source: REDHAT Type: UNKNOWN RHBA-2019:0862
Source: CCN Type: Kubernetes Web site Security release of Kubernetes affecting certain network configurations with CNI - Releases 1.11.9, 1.12.7, 1.13.5, and 1.14.0 - CVE-2019-9946
Source: XF Type: UNKNOWN kubernetes-cve20199946-weak-security(158803)
Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/containernetworking/plugins/pull/269#issuecomment-477683272
Source: CCN Type: Kubernetes GIT Repository build/gci: bump CNI version to 0.7.5 - CVE-2019-9946 #75455
Source: FEDORA Type: UNKNOWN FEDORA-2019-d2b57d3b19
Source: FEDORA Type: UNKNOWN FEDORA-2019-24217abfdf
Source: CONFIRM Type: Patch, Third Party Advisory https://security.netapp.com/advisory/ntap-20190416-0002/
Source: CCN Type: IBM Security Bulletin 882952 (API Connect) API Connect V2018 is impacted by a security degradation vulnerability in Kubernetes (CVE-2019-9946)
Source: CCN Type: IBM Security Bulletin 886609 (Cloud Private for Data) IBM Cloud Private for Data is affected multiple security vulnerabilities in IBM Cloud Private Kubernetes
Source: CCN Type: IBM Security Bulletin 1143454 (Watson Studio Local) Multiple Vulnerabilities in Kubernetes affects IBM Watson Studio Local
|
Vulnerable Configuration: | Configuration 1: cpe:/a:cncf:portmap:*:*:*:*:*:container_networking_interface:*:* (Version < 0.7.5)OR cpe:/a:kubernetes:kubernetes:*:*:*:*:*:*:*:* (Version < 1.11.9)OR cpe:/a:kubernetes:kubernetes:*:*:*:*:*:*:*:* (Version >= 1.12.0 and < 1.12.7)OR cpe:/a:kubernetes:kubernetes:*:*:*:*:*:*:*:* (Version >= 1.13.0 and < 1.13.5)OR cpe:/a:kubernetes:kubernetes:1.13.6:beta0:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha0:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha1:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha2:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha3:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:beta0:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:beta1:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:beta2:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:rc1:*:*:*:*:*:* Configuration 2: cpe:/a:netapp:cloud_insights:-:*:*:*:*:*:*:* Configuration RedHat 1: cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:* Configuration RedHat 2: cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:* Configuration CCN 1: cpe:/a:kubernetes:kubernetes:1.11.0:-:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.12.0:-:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.13.0:-:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.11.1:-:*:*:*:*:*:*OR cpe:/a:kubernetes:kubernetes:1.14.0:*:*:*:*:*:*:*AND cpe:/a:ibm:cloud_private:2.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:api_connect:2018.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:cloud_private:3.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:cloud_private:3.1.1:*:*:*:*:*:*:*OR cpe:/a:ibm:cloud_private:3.1.2:*:*:*:*:*:*:*OR cpe:/a:ibm:api_connect:2018.4.1.4:*:*:*:*:*:*:*OR cpe:/a:ibm:cloud_private:2.1.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |
cncf portmap *
kubernetes kubernetes *
kubernetes kubernetes *
kubernetes kubernetes *
kubernetes kubernetes 1.13.6 beta0
kubernetes kubernetes 1.14.0 alpha0
kubernetes kubernetes 1.14.0 alpha1
kubernetes kubernetes 1.14.0 alpha2
kubernetes kubernetes 1.14.0 alpha3
kubernetes kubernetes 1.14.0 beta0
kubernetes kubernetes 1.14.0 beta1
kubernetes kubernetes 1.14.0 beta2
kubernetes kubernetes 1.14.0 rc1
netapp cloud insights -
kubernetes kubernetes 1.11.0 -
kubernetes kubernetes 1.12.0 -
kubernetes kubernetes 1.13.0 -
kubernetes kubernetes 1.11.1 -
kubernetes kubernetes 1.14.0
ibm cloud private 2.1.0
ibm api connect 2018.1.0
ibm cloud private 3.1.0
ibm cloud private 3.1.1
ibm cloud private 3.1.2
ibm api connect 2018.4.1.4
ibm cloud private 2.1.0.0