CVE-2020-13597
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
03/06/2020
Last modified:
07/11/2023
Description
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node accepting route advertisement by default, allowing the attacker to redirect full or partial network traffic from the node to the compromised pod.
Impact
Base Score 3.x
3.50
Severity 3.x
LOW
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:projectcalico:calico:*:*:*:*:enterprise:*:*:* | 2.6.2 (including) | |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:* | 3.8.8 (including) | |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:enterprise:*:*:* | 2.7.0 (including) | 2.7.4 (including) |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:enterprise:*:*:* | 2.8.0 (including) | 2.8.2 (including) |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:* | 3.9.0 (including) | 3.9.5 (including) |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:* | 3.10.0 (including) | 3.10.3 (including) |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:* | 3.11.0 (including) | 3.11.2 (including) |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:* | 3.12.0 (including) | 3.12.1 (including) |
| cpe:2.3:a:projectcalico:calico:*:*:*:*:*:*:*:* | 3.13.0 (including) | 3.13.3 (including) |
| cpe:2.3:a:projectcalico:calico:3.14.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



