CVE-2022-29179
Improper Privilege Management in Cilium
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium's Kubernetes service account. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. There are no known workarounds available.
Cilium es un software de código abierto para proporcionar y asegurar la conectividad de red y el equilibrio de carga entre las cargas de trabajo de las aplicaciones. En versiones anteriores a 1.9.16, 1.10.11 y 1.11.15, si un atacante es capaz de llevar a cabo un escape de un contenedor que es ejecutado como root en un host donde está instalado Cilium, el atacante puede escalar privilegios a administrador del clúster usando la cuenta de servicio Kubernetes de Cilium. El problema ha sido corregido y el parche está disponible en las versiones 1.9.16, 1.10.11 y 1.11.5. No se presentan mitigaciones conocidas disponibles
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-13 CVE Reserved
- 2022-05-20 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/cilium/cilium/releases/tag/v1.10.11 | Release Notes | |
https://github.com/cilium/cilium/releases/tag/v1.11.5 | Release Notes | |
https://github.com/cilium/cilium/releases/tag/v1.9.16 | Release Notes | |
https://github.com/cilium/cilium/security/advisories/GHSA-fmrf-gvjp-5j5g | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cilium Search vendor "Cilium" | Cilium Search vendor "Cilium" for product "Cilium" | < 1.9.16 Search vendor "Cilium" for product "Cilium" and version " < 1.9.16" | - |
Affected
| ||||||
Cilium Search vendor "Cilium" | Cilium Search vendor "Cilium" for product "Cilium" | >= 1.10.0 < 1.10.11 Search vendor "Cilium" for product "Cilium" and version " >= 1.10.0 < 1.10.11" | - |
Affected
| ||||||
Cilium Search vendor "Cilium" | Cilium Search vendor "Cilium" for product "Cilium" | >= 1.11.0 < 1.11.5 Search vendor "Cilium" for product "Cilium" and version " >= 1.11.0 < 1.11.5" | - |
Affected
|