Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43415
HistorySep 28, 2023 - 7:30 a.m.

Insufficient Verification Of Data Authenticity

2023-09-2807:30:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
cilium
vulnerability
getpodmetadata
data authenticity
network policy
bypassing
software

CVSS3

9

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

github.com/cilium/cilium is vulnerable to Insufficient Verification Of Data Authenticity. The vulnerability is due to in GetPodMetadata as there is no check or sanitization for user changing namespace, service account or cluster name labels. This allow an attacker to utilize crafted pod labels during a pod update, and cilium incorrectly uses crafted pod labels to select the policies which apply to the workload in question and which could lead to network policy bypassing.

CVSS3

9

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Related for VERACODE:43415