Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/projectcalico/calico: CVE-2024-33522 #2801

Open
GoVulnBot opened this issue Apr 30, 2024 · 0 comments
Assignees
Labels

Comments

@GoVulnBot
Copy link

CVE-2024-33522 references github.com/projectcalico/calico, which may be a Go module.

Description:
In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/projectcalico/calico
      vulnerable_at: 2.6.12+incompatible
      packages:
        - package: Calico
summary: CVE-2024-33522 in github.com/projectcalico/calico
cves:
    - CVE-2024-33522
references:
    - report: https://github.com/projectcalico/calico/issues/7981
    - fix: https://github.com/projectcalico/calico/pull/8447
    - fix: https://github.com/projectcalico/calico/pull/8517
    - web: https://www.tigera.io/security-bulletins-tta-2024-001/
source:
    id: CVE-2024-33522

@tatianab tatianab self-assigned this Apr 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants