Vulnerability Description
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Cni Network Plugins | < 0.8.6 |
| Redhat | Openshift Container Platform | 4.0 |
| Fedoraproject | Fedora | 32 |
| Redhat | Enterprise Linux | 7.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00063.htmlBroken LinkThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00065.htmlBroken LinkThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10749Issue TrackingThird Party Advisory
- https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00063.htmlBroken LinkThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00065.htmlBroken LinkThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10749Issue TrackingThird Party Advisory
- https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-10749?
CVE-2020-10749 is a vulnerability with a CVSS score of 6.0 (MEDIUM). A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A ma...
How severe is CVE-2020-10749?
CVE-2020-10749 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10749?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Cni Network Plugins, Redhat Openshift Container Platform, Fedoraproject Fedora, Redhat Enterprise Linux.