Vulnerability Name: CVE-2019-9946 (CCN-158803) Assigned: 2019-03-28 Published: 2019-03-28 Updated: 2020-08-24 Summary: Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N )6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): HighAvailibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N )4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
6.5 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L )5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-670 CWE-841 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2019-9946 Source: CCN Type: IBM Security Bulletin 878460 (Cloud Private)Multiple Security Vulnerabilities affect IBM Cloud Private Kubernetes Source: CCN Type: IBM Security Bulletin 879585 (Cloud Kubernetes Service)IBM Cloud Kubernetes Service is affected by a CNI security vulnerability Source: REDHAT Type: UNKNOWNRHBA-2019:0862 Source: CCN Type: Kubernetes Web siteSecurity release of Kubernetes affecting certain network configurations with CNI - Releases 1.11.9, 1.12.7, 1.13.5, and 1.14.0 - CVE-2019-9946 Source: XF Type: UNKNOWNkubernetes-cve20199946-weak-security(158803) Source: CONFIRM Type: Patch, Third Party Advisoryhttps://github.com/containernetworking/plugins/pull/269#issuecomment-477683272 Source: CCN Type: Kubernetes GIT Repositorybuild/gci: bump CNI version to 0.7.5 - CVE-2019-9946 #75455 Source: FEDORA Type: UNKNOWNFEDORA-2019-d2b57d3b19 Source: FEDORA Type: UNKNOWNFEDORA-2019-24217abfdf Source: CONFIRM Type: Patch, Third Party Advisoryhttps://security.netapp.com/advisory/ntap-20190416-0002/ Source: CCN Type: IBM Security Bulletin 882952 (API Connect)API Connect V2018 is impacted by a security degradation vulnerability in Kubernetes (CVE-2019-9946) Source: CCN Type: IBM Security Bulletin 886609 (Cloud Private for Data)IBM Cloud Private for Data is affected multiple security vulnerabilities in IBM Cloud Private Kubernetes Source: CCN Type: IBM Security Bulletin 1143454 (Watson Studio Local)Multiple Vulnerabilities in Kubernetes affects IBM Watson Studio Local Vulnerable Configuration: Configuration 1 :cpe:/a:cncf:portmap:*:*:*:*:*:container_networking_interface:*:* (Version < 0.7.5)OR cpe:/a:kubernetes:kubernetes:*:*:*:*:*:*:*:* (Version < 1.11.9) OR cpe:/a:kubernetes:kubernetes:*:*:*:*:*:*:*:* (Version >= 1.12.0 and < 1.12.7) OR cpe:/a:kubernetes:kubernetes:*:*:*:*:*:*:*:* (Version >= 1.13.0 and < 1.13.5) OR cpe:/a:kubernetes:kubernetes:1.13.6:beta0:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha0:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha1:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha2:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:alpha3:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:beta0:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:beta1:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:beta2:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:rc1:*:*:*:*:*:* Configuration 2 :cpe:/a:netapp:cloud_insights:-:*:*:*:*:*:*:* Configuration RedHat 1 :cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:* Configuration RedHat 2 :cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:* Configuration CCN 1 :cpe:/a:kubernetes:kubernetes:1.11.0:-:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.12.0:-:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.13.0:-:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.11.1:-:*:*:*:*:*:* OR cpe:/a:kubernetes:kubernetes:1.14.0:*:*:*:*:*:*:* AND cpe:/a:ibm:cloud_private:2.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:api_connect:2018.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:cloud_private:3.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:cloud_private:3.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:cloud_private:3.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:api_connect:2018.4.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:cloud_private:2.1.0:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
cncf portmap *
kubernetes kubernetes *
kubernetes kubernetes *
kubernetes kubernetes *
kubernetes kubernetes 1.13.6 beta0
kubernetes kubernetes 1.14.0 alpha0
kubernetes kubernetes 1.14.0 alpha1
kubernetes kubernetes 1.14.0 alpha2
kubernetes kubernetes 1.14.0 alpha3
kubernetes kubernetes 1.14.0 beta0
kubernetes kubernetes 1.14.0 beta1
kubernetes kubernetes 1.14.0 beta2
kubernetes kubernetes 1.14.0 rc1
netapp cloud insights -
kubernetes kubernetes 1.11.0 -
kubernetes kubernetes 1.12.0 -
kubernetes kubernetes 1.13.0 -
kubernetes kubernetes 1.11.1 -
kubernetes kubernetes 1.14.0
ibm cloud private 2.1.0
ibm api connect 2018.1.0
ibm cloud private 3.1.0
ibm cloud private 3.1.1
ibm cloud private 3.1.2
ibm api connect 2018.4.1.4
ibm cloud private 2.1.0.0