CVE-2019-9946

UnknownEPSS 3.12%

Last modified

CVE-2019-9946 is a vulnerability of currently unknown severity. Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. EPSS estimates a 3.12% chance of exploitation in the next 30 days.

Description

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

Metrics

EPSS Probability
3.12%

86.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
CncfPortmap< 0.7.5
KubernetesKubernetes< 1.11.9
KubernetesKubernetes>= 1.12.0, < 1.12.7
KubernetesKubernetes>= 1.13.0, < 1.13.5
KubernetesKubernetes1.13.6Beta0
KubernetesKubernetes1.14.0Alpha0
NetappCloud InsightsAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-9946?
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
How severe is CVE-2019-9946?
Severity scoring for CVE-2019-9946 is pending analysis. The EPSS model estimates a 3.12% probability of exploitation in the next 30 days.
How do I fix CVE-2019-9946?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-9946?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST