• CVE-2022-29179

发布时间: 2022年8月11日

修改时间: 2022年8月11日

概要

Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium s Kubernetes service account. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. There are no known workarounds available.

CVSS v3 指标

NVD openEuler
CVSS评分 8.2 8.2
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required High High
User Interaction None None
Scope Changed Changed
Confidentiality High High
Integrity High High
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-1903 Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium s Kubernetes service account. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. There are no known workarounds available. 2022年8月11日

影响产品

产品 状态
KY3.4-4A cilium Unaffected
KY3.4-5 cilium Unaffected
KY3.5.1 cilium Unaffected