CVE Database
/

CVE-2019-9946

Back to search

CVE-2019-9946

Published: Apr 2, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHBA-2019:0862
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-d2b57d3b19
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-24217abfdf
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now