QID 982346

QID 982346: Go (go) Security Update for github.com/ovn-org/ovn-kubernetes (GHSA-57v4-m9jx-mh8r)

A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or availability of a service.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.6 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-57v4-m9jx-mh8r for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982346

    Software Advisories
    Advisory ID Software Component Link
    GHSA-57v4-m9jx-mh8r github.com/ovn-org/ovn-kubernetes URL Logo github.com/advisories/GHSA-57v4-m9jx-mh8r