SB2020070182 - Red Hat Enterprise Linux 7 Extras update for containernetworking-plugins



SB2020070182 - Red Hat Enterprise Linux 7 Extras update for containernetworking-plugins

Published: July 1, 2020

Security Bulletin ID SB2020070182
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient verification of data authenticity (CVE-ID: CVE-2020-10749)

The vulnerability allows a remote attacker to perform a man-in-the-Middle attack.

The vulnerability exists due to insufficient verification of data authenticity in CNI plugins when processing IPV6 router advertisements. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.


Remediation

Install update from vendor's website.