Vulnerabilities > CVE-2021-3499 - Incorrect Authorization vulnerability in OVN Ovn-Kubernetes 0.1.0/0.2.0/0.3.0

047910
CVSS 5.6 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
LOW
network
high complexity
ovn
CWE-863

Summary

A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or availability of a service.

Vulnerable Configurations

Part Description Count
Application
Ovn
5

Common Weakness Enumeration (CWE)