Database/Container, Kubernetes & orchestration
CNI portmap plugin: portmap inserts rules ahead of the KUBE-SERVICES chain, so hostPort traffic bypasses NetworkPolicy
CVSS 7.5CVE-2019-9946Container, Kubernetes & orchestrationcurated
Impact
portmap inserts rules ahead of the KUBE-SERVICES chain, so hostPort traffic bypasses NetworkPolicy
Who can reach it
Any pod on the cluster network
What to do
Upgrade the CNI plugins package on every node; block hostPort for tenants
References
Related entries
- Firecracker: Unbounded serial console buffer growth leaks host memoryCVE-2020-27174 · FirecrackerHigh
- Envoy: HTTP/1.1 requests or responses with many 1-byte chunks exhaust proxy memoryCVE-2020-8659 · Envoy proxy (HTTP/1.1 codec, small-chunk buffering)High
- Envoy: generating internal responses to pipelined HTTP/1.1 requests consumes excessive memoryCVE-2020-8661 · Envoy proxy (internal responses to pipelined HTTP/1.1 requests)High
- Argo CD: /api/version leaks internal system information without authenticationCVE-2021-26923 · Argo CDHigh
- CRI-O: Unbounded ExecSync output exhausts node memory or diskCVE-2022-1708 · CRI-OHigh
- Istio: Crafted message crashes istiodCVE-2022-23635 · IstioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.