CVE-2021-20206
Summary
| CVE | CVE-2021-20206 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-26 22:15:00 UTC |
| Updated | 2023-11-07 03:29:00 UTC |
| Description | An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Directory Traversal in github.com/containernetworking/cni/pkg/invoke | Snyk |
MISC |
snyk.io |
|
| 1919391 – (CVE-2021-20206) CVE-2021-20206 containernetworking-cni: Arbitrary path injection via type field in CNI configuration |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180278 Debian Security Update for golang-github-appc-cni (CVE-2021-20206)
- 501808 Alpine Linux Security Update for buildah
- 504590 Alpine Linux Security Update for buildah
- 751850 OpenSUSE Security Update for buildah (openSUSE-SU-2022:0770-1)
- 752641 SUSE Enterprise Linux Security Update for buildah (SUSE-SU-2022:3480-1)
- 752726 SUSE Enterprise Linux Security Update for buildah (SUSE-SU-2022:3766-1)
- 752819 SUSE Enterprise Linux Security Update for cni-plugins (SUSE-SU-2022:4151-1)
- 752906 SUSE Enterprise Linux Security Update for cni (SUSE-SU-2022:4150-1)
- 753019 SUSE Enterprise Linux Security Update for cni (SUSE-SU-2022:4592-1)
- 753052 SUSE Enterprise Linux Security Update for cni-plugins (SUSE-SU-2022:4593-1)
- 753101 SUSE Enterprise Linux Security Update for buildah (SUSE-SU-2022:0770-1)
- 753242 SUSE Enterprise Linux Security Update for buildah (SUSE-SU-2022:3655-1)
- 753592 SUSE Enterprise Linux Security Update for podman (SUSE-SU-2023:0187-1)
- 753659 SUSE Enterprise Linux Security Update for podman (SUSE-SU-2023:0326-1)