Tigera

Calico Enterprise

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 30.07.2026 14:45:04
  • Zuletzt bearbeitet 08.08.2026 01:20:02

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrie...

  • EPSS 0.22%
  • Veröffentlicht 30.07.2026 14:45:04
  • Zuletzt bearbeitet 08.08.2026 01:16:27

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user ...

  • EPSS 0.37%
  • Veröffentlicht 30.07.2026 14:45:04
  • Zuletzt bearbeitet 08.08.2026 01:10:43

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not corre...

  • EPSS 0.32%
  • Veröffentlicht 28.05.2026 15:47:42
  • Zuletzt bearbeitet 05.06.2026 17:03:34

When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unmarshaled co...

  • EPSS 0.22%
  • Veröffentlicht 28.05.2026 15:47:42
  • Zuletzt bearbeitet 29.05.2026 15:39:34

When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the c...

  • EPSS 0.22%
  • Veröffentlicht 29.04.2024 23:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploitin...

  • EPSS 0.72%
  • Veröffentlicht 06.11.2023 16:15:42
  • Zuletzt bearbeitet 21.11.2024 08:21:11

In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Han...

  • EPSS 0.57%
  • Veröffentlicht 06.06.2022 18:15:09
  • Zuletzt bearbeitet 30.09.2025 18:45:43

Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a floating IP ...