CVE-2022-0567 is a critical flaw in ovn-kubernetes that enables a privileged attacker to bypass ingress network policies by creating a specially crafted egress policy. This allows unauthorized access to other pods within a cluster, leading to potential information disclosure and other attacks. With a CVSS score of 9.1 (CRITICAL), the vulnerability is network-exploitable with high privileges and can result in complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating awareness and potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.7.47CPE matchmatch criteria | cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:* | ||
>= 4.8.0, < 4.8.36CPE matchmatch criteria | cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:* | ||
>= 4.9.0, < 4.9.27CPE matchmatch criteria | cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:* | ||
>= 4.10.0, < 4.10.8CPE matchmatch criteria | cpe:2.3:a:ovn:ovn-kubernetes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.