ovn-kubernetes: Ingress network policy can be overruled by egress network policy on another pod
Published Apr 20, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.04%
Description
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.
Affected products
- Vendor n/a Product Ovn-Kubernetes Defaultunknown
Affected
- OCP v 4.10.8
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Ovn-Kubernetes | unknown | Affected
|
- < 4.7.47
- ≥ 4.8.0 · < 4.8.36
- ≥ 4.9.0 · < 4.9.27
- ≥ 4.10.0 · < 4.10.8
No data.
Red Hat OpenShift Container Platform 4.10
openshift4/ose-ovn-kubernetes:v4.10.0-202203311829.p0.gc580607.assembly.stream
Fixed · RHSA-2022:1162
Red Hat OpenShift Container Platform 4.7
openshift4/ose-ovn-kubernetes:v4.7.0-202203311831.p0.g385bc8f.assembly.stream
Fixed · RHSA-2022:1166
Red Hat OpenShift Container Platform 4.8
openshift4/ose-ovn-kubernetes:v4.8.0-202203311830.p0.gaa2c3f4.assembly.stream
Fixed · RHSA-2022:1154
Red Hat OpenShift Container Platform 4.9
openshift4/ose-ovn-kubernetes:v4.9.0-202203311521.p0.ga6eec84.assembly.stream
Fixed · RHSA-2022:1158
Red Hat OpenShift Container Platform 3.11
openshift3/ose-ovn-kubernetes
Not affected
Red Hat OpenShift Container Platform 3.11
openvswitch-ovn-kubernetes
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.10 | openshift4/ose-ovn-kubernetes:v4.10.0-202203311829.p0.gc580607.assembly.stream | Fixed | RHSA-2022:1162 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ovn-kubernetes:v4.7.0-202203311831.p0.g385bc8f.assembly.stream | Fixed | RHSA-2022:1166 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-ovn-kubernetes:v4.8.0-202203311830.p0.gaa2c3f4.assembly.stream | Fixed | RHSA-2022:1154 |
| Red Hat OpenShift Container Platform 4.9 | openshift4/ose-ovn-kubernetes:v4.9.0-202203311521.p0.ga6eec84.assembly.stream | Fixed | RHSA-2022:1158 |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-ovn-kubernetes | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openvswitch-ovn-kubernetes | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2022-0567 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2053326 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15685 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0567
- https://www.cve.org/CVERecord?id=CVE-2022-0567
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0567 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2053326 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15685 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0567 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0567 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data