CVE-2021-20206

An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
linuxfoundationcontainer_network_interface
𝑥
< 0.8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-appc-cni
bookworm
1.1.2-1
fixed
bullseye
0.8.1-1
fixed
buster
postponed
sid
1.1.2-1
fixed
stretch
no-dsa
trixie
1.1.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-appc-cni
bionic
needs-triage
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
buildah
suse enterprise sap 15 SP5
1.29.1-150500.1.13
fixed
suse enterprise sap 15 SP6
1.34.1-150500.3.7.1
fixed
suse enterprise sap 15 SP7
1.35.5-150500.3.34.1
fixed
suse enterprise server 15 SP5
1.29.1-150500.1.13
fixed
suse enterprise server 15 SP6
1.34.1-150500.3.7.1
fixed
suse enterprise server 15 SP7
1.35.5-150500.3.34.1
fixed
cni
suse enterprise sap 15 SP5
1.1.2-150500.1.20
fixed
suse enterprise sap 15 SP6
1.1.2-150500.3.2.1
fixed
suse enterprise sap 15 SP7
1.1.2-150500.3.2.1
fixed
suse enterprise server 15 SP5
1.1.2-150500.1.20
fixed
suse enterprise server 15 SP6
1.1.2-150500.3.2.1
fixed
suse enterprise server 15 SP7
1.1.2-150500.3.2.1
fixed
cni-plugins
suse enterprise sap 15 SP5
1.1.1-150500.1.19
fixed
suse enterprise sap 15 SP6
1.1.1-150500.3.2.1
fixed
suse enterprise sap 15 SP7
1.1.1-150500.3.2.1
fixed
suse enterprise server 15 SP5
1.1.1-150500.1.19
fixed
suse enterprise server 15 SP6
1.1.1-150500.3.2.1
fixed
suse enterprise server 15 SP7
1.1.1-150500.3.2.1
fixed
podman
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-cni-config
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
podman-docker
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-remote
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podmansh
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed