CVE-2019-9946

Source
https://cve.org/CVERecord?id=CVE-2019-9946
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9946.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-9946
Downstream
Related
Published
2019-04-02T18:30:26.583Z
Modified
2026-02-24T11:33:38.308835Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

References

Affected packages

Git / github.com/kubernetes/kubelet

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9946.json"

Git / github.com/kubernetes/kubernetes

Affected ranges

Type
GIT
Repo
https://github.com/kubernetes/kubernetes
Events

Affected versions

v1.*
v1.12.0
v1.12.1
v1.12.1-beta.0
v1.12.2
v1.12.2-beta.0
v1.12.3
v1.12.3-beta.0
v1.12.4
v1.12.4-beta.0
v1.12.5
v1.12.5-beta.0
v1.12.6
v1.12.6-beta.0
v1.12.7-beta.0
v1.13.0
v1.13.1
v1.13.1-beta.0
v1.13.2
v1.13.2-beta.0
v1.13.3
v1.13.3-beta.0
v1.13.4
v1.13.4-beta.0
v1.13.5-beta.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9946.json"