Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-26278— Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilities

Quick assessment

Affected
weaveworks weave
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weaveworks Weave Net是英国Weaveworks公司的一款云原生网络工具包。 Weave Net 存在安全漏洞,攻击者可利用该漏洞接管集群中的任何主机。

CVSS 5.8 · Medium EPSS 0.74% · P52
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-26278

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilities
Source: CVE Program / CVE List V5
Vulnerability Description
Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. Weave Net before version 2.8.0 has a vulnerability in which can allow an attacker to take over any host in the cluster. Weave Net is supplied with a manifest that runs pods on every node in a Kubernetes cluster, which are responsible for managing network connections for all other pods in the cluster. This requires a lot of power over the host, and the manifest sets `privileged: true`, which gives it that power. It also set `hostPID: true`, which gave it the ability to access all other processes on the host, and write anywhere in the root filesystem of the host. This setting was not necessary, and is being removed. You are only vulnerable if you have an additional vulnerability (e.g. a bug in Kubernetes) or misconfiguration that allows an attacker to run code inside the Weave Net pod, No such bug is known at the time of release, and there are no known instances of this being exploited. Weave Net 2.8.0 removes the hostPID setting and moves CNI plugin install to an init container. Users who do not update to 2.8.0 can edit the hostPID line in their existing DaemonSet manifest to say false instead of true, arrange some other way to install CNI plugins (e.g. Ansible) and remove those mounts from the DaemonSet manifest.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
带着不必要的权限执行
Source: CVE Program / CVE List V5
Vulnerability Title
Weaveworks Weave Net 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Weaveworks Weave Net是英国Weaveworks公司的一款云原生网络工具包。 Weave Net 存在安全漏洞,攻击者可利用该漏洞接管集群中的任何主机。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
weaveworks weave < 2.8.0 -

II. Public POCs for CVE-2020-26278

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-26278

登录查看更多情报信息。

Patches & Fixes for CVE-2020-26278 (2)

Vendor Advisories for CVE-2020-26278 (1)

Other References for CVE-2020-26278 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2020-26278

No comments yet


Leave a comment