CVE-2020-13597

Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node accepting route advertisement by default, allowing the attacker to redirect full or partial network traffic from the node to the compromised pod.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:projectcalico:calico:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:*
cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:*
cpe:2.3:a:projectcalico:calico:3.14.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:01

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : 3.5
v2 : 2.1
v3 : 6.0
References () https://github.com/kubernetes/kubernetes/issues/91507 - Issue Tracking, Third Party Advisory () https://github.com/kubernetes/kubernetes/issues/91507 - Issue Tracking, Third Party Advisory
References () https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8 - () https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8 -
References () https://www.projectcalico.org/security-bulletins/ - Vendor Advisory () https://www.projectcalico.org/security-bulletins/ - Vendor Advisory

07 Nov 2023, 03:16

Type Values Removed Values Added
References
  • {'url': 'https://groups.google.com/forum/#!topic/kubernetes-security-announce/BMb_6ICCfp8', 'name': 'https://groups.google.com/forum/#!topic/kubernetes-security-announce/BMb_6ICCfp8', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • () https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8 -

Information

Published : 2020-06-03 17:15

Updated : 2024-11-21 05:01


NVD link : CVE-2020-13597

Mitre link : CVE-2020-13597

CVE.ORG link : CVE-2020-13597


JSON object : View

Products Affected

projectcalico

  • calico
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor