CVE-2022-29179
Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium's Kubernetes…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium's Kubernetes service account. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. There are no known workarounds available.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- cilium/cilium
- Source
- security-advisories@github.com
References
- https://github.com/cilium/cilium/releases/tag/v1.10.11Release Notes, Third Party Advisory
- https://github.com/cilium/cilium/releases/tag/v1.11.5Release Notes, Third Party Advisory
- https://github.com/cilium/cilium/releases/tag/v1.9.16Release Notes, Third Party Advisory
- https://github.com/cilium/cilium/security/advisories/GHSA-fmrf-gvjp-5j5gThird Party Advisory
- https://github.com/cilium/cilium/releases/tag/v1.10.11Release Notes, Third Party Advisory
- https://github.com/cilium/cilium/releases/tag/v1.11.5Release Notes, Third Party Advisory
- https://github.com/cilium/cilium/releases/tag/v1.9.16Release Notes, Third Party Advisory
- https://github.com/cilium/cilium/security/advisories/GHSA-fmrf-gvjp-5j5gThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.