Vulnerabilities > CVE-2019-9946 - Always-Incorrect Control Flow Implementation vulnerability in multiple products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
kubernetes
cncf
netapp
CWE-670
nessus

Summary

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

Vulnerable Configurations

Part Description Count
Application
Kubernetes
645
Application
Cncf
22
Application
Netapp
1

Nessus

  • NASL familyPhotonOS Local Security Checks
    NASL idPHOTONOS_PHSA-2019-2_0-0148_KUBERNETES.NASL
    descriptionAn update of the kubernetes package has been released.
    last seen2020-06-01
    modified2020-06-02
    plugin id124861
    published2019-05-14
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/124861
    titlePhoton OS 2.0: Kubernetes PHSA-2019-2.0-0148
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2019-D2B57D3B19.NASL
    descriptionResolves: #1715758 - CVE-2019-9946 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id125867
    published2019-06-13
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125867
    titleFedora 30 : containernetworking-plugins (2019-d2b57d3b19)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2019-24217ABFDF.NASL
    descriptionResolves: #1715758 - CVE-2019-9946 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id125932
    published2019-06-17
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125932
    titleFedora 29 : containernetworking-plugins (2019-24217abfdf)

Redhat

advisories
rhsa
idRHBA-2019:0862
rpms
  • containernetworking-plugins-0:0.7.5-2.el7
  • containernetworking-plugins-debuginfo-0:0.7.5-2.el7