In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes the live Kubernetes ServiceAccount bearer token before logging, exposing the token to any authenticated user with pods/log permission in the namespace with calico-node. The token holds patch privileges on pods/status, enabling annotation-based attacks against cluster workloads. The default kubeconfig-based authentication path is not affected. This is a direct regression of TTA-2018-001.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.21.7CPE matchmatch criteria | cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:* | ||
< 3.32.0CPE matchmatch criteria | cpe:2.3:a:tigera:calico:*:*:*:*:open_source:*:*:* | ||
< 22.4.0CPE matchmatch criteria | cpe:2.3:a:tigera:calico:*:*:*:*:cloud:*:*:* | ||
>= 3.22.0, < 3.22.3CPE matchmatch criteria | cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:* | ||
>= 0, < 3.31.6CPE match | cpe:2.3:a:tigera:calico:*:*:*:*:cloud:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.