VYPR

Go modules package

github.com/projectcalico/calico

pkg:golang/github.com/projectcalico/calico

Vulnerabilities (4)

  • CVE-2024-33522MedApr 29, 2024
    affected < 3.26.5fixed 3.26.5

    In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calic

  • CVE-2023-41378Nov 6, 2023
    affected >= 3.26.0, < 3.26.3fixed 3.26.3

    In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed ins

  • CVE-2022-28224Jun 6, 2022
    affected >= 3.22.0, < 3.22.2fixed 3.22.2

    Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a floating IP annotation to a pod even if th

  • CVE-2020-13597Jun 3, 2020
    affected >= 3.14.0, < 3.14.1fixed 3.14.1

    Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node a