Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2022-28224
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Calico and Calico Enterprise may be vulnerable to route hijacking with the floating IP feature
Source: NVD (National Vulnerability Database)
Vulnerability Description
Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a floating IP annotation to a pod even if the feature is not enabled. This may allow the attacker to intercept and reroute traffic to their compromised pod.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Tigera Calico 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tigera Calico是美国Tigera公司的一套针对容器、虚拟机和主机工作负载的开源网络安全解决方案。 Tigera Calico 3.22.1版本及之前版本、Calico Enterprise 3.12.0版本及之前版本存在安全漏洞,该漏洞源于容易受到浮动 IP 功能的路由劫持。攻击者利用该漏洞拦截流量。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
TigeraCalico Enterprise unspecified ~ v3.12.0 -
Project CalicoCalico unspecified ~ v3.22.1 -
II. Public POCs for CVE-2022-28224
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2022-28224
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2022-28224

No comments yet


Leave a comment