Use of insecure channel - Source code In github.com/containernetworking/plugins
Description
containernetworking/plugins vulnerable to MitM attacks A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.8.6 | ||
debian 12 | 0.8.6-1 | ||
debian 13 | 0.8.6-1 | ||
debian 11 | 0.8.6-1 | ||
debian 14 | 0.8.6-1 | ||
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7.