CVE-2022-29179
Improper Privilege Management in Cilium
7.5
HIGH
CVSS 3.1
EPSS 0.36%
描述
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium's Kubernetes service account. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. There are no known workarounds available.
如何修補 CVE-2022-29179
要修補 CVE-2022-29179,請將受影響套件升級到下列已修補版本。
- —升級至 1.9.16 或更新版本
- —升級至 1.9.16 或更新版本
- —升級至 1.9.16 或更新版本
- —升級至 1.9.16 或更新版本
- —升級至 1.9.16 或更新版本
- —升級至 1.9.16 或更新版本
- —升級至 1.9.16 或更新版本
- —升級至 1.11.5 或更新版本
- —升級至 1.9.16 或更新版本
CVE-2022-29179 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(9)
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
- >= 1.11.0, < 1.11.5
- from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |