CVE-2020-13597
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused.
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node accepting route advertisement by default, allowing the attacker to redirect full or partial network traffic from the node to the compromised pod.
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-201, CWE-200
- Affected
- projectcalico/calico
- Source
- psirt@tigera.io
References
- https://github.com/kubernetes/kubernetes/issues/91507Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8
- https://www.projectcalico.org/security-bulletins/Vendor Advisory
- https://github.com/kubernetes/kubernetes/issues/91507Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21topic/kubernetes-security-announce/BMb_6ICCfp8
- https://www.projectcalico.org/security-bulletins/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.