CVE-2019-9946 Details
Description
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-670 | Always-Incorrect Control Flow Implementation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cncf portmap | < 0.7.5 |
CPE
Remediation
| |
| kubernetes kubernetes | < 1.11.9 >= 1.12.0, < 1.12.7 >= 1.13.0, < 1.13.5 1.13.6 beta0 1.14.0 alpha0 1.14.0 alpha1 1.14.0 alpha2 1.14.0 alpha3 1.14.0 beta0 1.14.0 beta1 1.14.0 beta2 1.14.0 rc1 |
CPE
Remediation
| |
| netapp cloud insights | All versions |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Jun 15, 2019 | CVE Modified | [email protected] |
| Jun 12, 2019 | CVE Modified | [email protected] |
| May 30, 2019 | CVE Modified | [email protected] |
| Apr 16, 2019 | Modified Analysis | [email protected] |
| Apr 16, 2019 | CVE Modified | [email protected] |
| Apr 4, 2019 | Initial Analysis | [email protected] |