CVE-2022-28224

MEDIUM

Calico < 3.20.5, Calico Enterprise < 3.11.4, Calico 3.22.0-3.22.1 - Route Hijacking via Floating IP Annotation

Title source: llm
STIX 2.1

Description

Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a floating IP annotation to a pod even if the feature is not enabled. This may allow the attacker to intercept and reroute traffic to their compromised pod.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0055
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H

Details

CWE
CWE-201 CWE-20 CWE-200
Status published
Products (4)
projectcalico/calico 3.22.0 - 3.22.2Go
tigera/calico < 3.20.5
tigera/calico_enterprise 3.12.0
tigera/calico_enterprise < 3.11.4
Published Jun 06, 2022
Tracked Since Feb 18, 2026