Search

Find a vulnerability

Search criteria

    1 vulnerability found for calico_cloud by tigera

    CVE-2024-33522 (GCVE-0-2024-33522)

    Vulnerability from cvelistv5 – Published: 2024-04-29 22:19 – Updated: 2024-08-02 02:36
    VLAI
    Title
    Privilege escalation in Calico CNI install binary
    Summary
    In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-12 16:51 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    Tigera Calico Affected: 0 , < v3.26.5 (semver)
    Affected: v3.27.0 , < v3.27.3 (semver)
    Unaffected: v3.28.0
    Create a notification for this product.
    Tigera Calico Enterprise Affected: 0 , < v3.17.4 (semver)
    Affected: v3.18.0 , < v3.18.2 (semver)
    Affected: v3.19.0-1.0 , < v3.19.0-2.0 (semver)
    Create a notification for this product.
    Tigera Calico Cloud Affected: 0 , < v19.3.0 (semver)
    Create a notification for this product.
    tigera calico Affected: 0 , < v3.26.5 (semver)
    Affected: v3.27.0 , < v3.27.3 (semver)
    Unaffected: v3.28.0
        cpe:2.3:a:tigera:calico:*:*:*:*:*:*:*:*
    Create a notification for this product.
    tigera calico_enterprise Affected: 0 , < v3.17.4 (semver)
    Affected: v3.18.0 , < v3.18.2 (semver)
    Affected: v3.19.0-1.0 , < v3.19.0-2.0 (semver)
        cpe:2.3:a:tigera:calico_enterprise:*:*:*:*:*:*:*:*
    Create a notification for this product.
    tigera calico_cloud Affected: 0 , < v19.3.0 (semver)
        cpe:2.3:a:tigera:calico_cloud:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-04-29 19:57
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tigera:calico:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "calico",
                "vendor": "tigera",
                "versions": [
                  {
                    "lessThan": "v3.26.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "v3.27.3",
                    "status": "affected",
                    "version": "v3.27.0",
                    "versionType": "semver"
                  },
                  {
                    "status": "unaffected",
                    "version": "v3.28.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tigera:calico_enterprise:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "calico_enterprise",
                "vendor": "tigera",
                "versions": [
                  {
                    "lessThan": "v3.17.4",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "v3.18.2",
                    "status": "affected",
                    "version": "v3.18.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "v3.19.0-2.0",
                    "status": "affected",
                    "version": "v3.19.0-1.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:tigera:calico_cloud:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "calico_cloud",
                "vendor": "tigera",
                "versions": [
                  {
                    "lessThan": "v19.3.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-33522",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-12T16:51:23.967533Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-12T17:09:59.549Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T02:36:04.113Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "exploit",
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://github.com/projectcalico/calico/issues/7981"
              },
              {
                "tags": [
                  "patch",
                  "x_transferred"
                ],
                "url": "https://github.com/projectcalico/calico/pull/8447"
              },
              {
                "tags": [
                  "patch",
                  "x_transferred"
                ],
                "url": "https://github.com/projectcalico/calico/pull/8517"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://www.tigera.io/security-bulletins-tta-2024-001/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "cni-plugin",
              "product": "Calico",
              "repo": "https://www.tigera.io/tigera-products/calico/",
              "vendor": "Tigera",
              "versions": [
                {
                  "lessThan": "v3.26.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "v3.27.3",
                  "status": "affected",
                  "version": "v3.27.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "v3.28.0"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "cni-plugin",
              "product": "Calico Enterprise ",
              "vendor": "Tigera",
              "versions": [
                {
                  "lessThan": "v3.17.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "v3.18.2",
                  "status": "affected",
                  "version": "v3.18.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "v3.19.0-2.0",
                  "status": "affected",
                  "version": "v3.19.0-1.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "cni-plugin",
              "product": "Calico Cloud",
              "vendor": "Tigera",
              "versions": [
                {
                  "lessThan": "v19.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Christopher Alonso (Github: @latortuga71)"
            },
            {
              "lang": "en",
              "type": "remediation reviewer",
              "value": "Anthony Tam"
            },
            {
              "lang": "en",
              "type": "remediation verifier",
              "value": "Behnam Shobiri"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Pedro Coutinho"
            },
            {
              "lang": "en",
              "type": "remediation reviewer",
              "value": "Matt Dupre"
            }
          ],
          "datePublic": "2024-04-29T19:57:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: transparent;\"\u003eIn vulnerable \u003c/span\u003e\u003cspan style=\"background-color: transparent;\"\u003eversions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-29T22:19:06.908Z",
            "orgId": "e6d453f4-3dae-4941-bcea-9af25f4e824d",
            "shortName": "Tigera"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/projectcalico/calico/issues/7981"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/projectcalico/calico/pull/8447"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/projectcalico/calico/pull/8517"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.tigera.io/security-bulletins-tta-2024-001/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Privilege escalation in Calico CNI install binary",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e6d453f4-3dae-4941-bcea-9af25f4e824d",
        "assignerShortName": "Tigera",
        "cveId": "CVE-2024-33522",
        "datePublished": "2024-04-29T22:19:06.908Z",
        "dateReserved": "2024-04-23T16:32:33.170Z",
        "dateUpdated": "2024-08-02T02:36:04.113Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }