CVE-2022-0567
20.04.2022, 16:15
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.Enginsight
Vendor | Product | Version |
---|---|---|
ovn | ovn-kubernetes | 𝑥 < 4.7.47 |
ovn | ovn-kubernetes | 4.8.0 ≤ 𝑥 < 4.8.36 |
ovn | ovn-kubernetes | 4.9.0 ≤ 𝑥 < 4.9.27 |
ovn | ovn-kubernetes | 4.10.0 ≤ 𝑥 < 4.10.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration