发布时间: 2024年8月23日
修改时间: 2024年8月23日
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
NVD | openEuler | |
---|---|---|
CVSS评分 | 6.0 | 6.0 |
Attack Vector | Network | Network |
Attack Complexity | High | High |
Privileges Required | Low | Low |
User Interaction | None | None |
Scope | Changed | Changed |
Confidentiality | Low | Low |
Integrity | Low | Low |
Availability | Low | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-3414 | A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container. | 2024年8月23日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5A | containernetworking-plugins | Unaffected |
KY3.5.2 | containernetworking-plugins | Unaffected |
V6 | containernetworking-plugins | Unaffected |