Lucene search

K
osvGoogleOSV:GHSA-FX6X-H9G4-56F8
HistoryMay 24, 2022 - 5:19 p.m.

containernetworking/plugins vulnerable to MitM attacks

2022-05-2417:19:02
Google
osv.dev
13

0.001 Low

EPSS

Percentile

40.3%

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.