CVE-2020-13597Medium· 6.0▾ SunlitExposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node accepting route advertisement by default, allowing the attacker to redirect full or partial network traffic from the node to the compromised pod.
github.com/projectcalico/calico >= 3.14.0, < 3.14.1github.com/projectcalico/calico >= 3.13.0, < 3.13.4github.com/projectcalico/calico >= 3.12.0, < 3.12.2github.com/projectcalico/calico >= 3.11.0, < 3.11.3github.com/projectcalico/calico >= 3.10.0, < 3.10.4github.com/projectcalico/calico >= 3.9.0, < 3.9.6github.com/projectcalico/calico < 3.8.9Upgrade to a patched release:
github.com/projectcalico/calico 3.14.1github.com/projectcalico/calico 3.13.4github.com/projectcalico/calico 3.12.2github.com/projectcalico/calico 3.11.3github.com/projectcalico/calico 3.10.4github.com/projectcalico/calico 3.9.6github.com/projectcalico/calico 3.8.9Connected by shared product, vendor, weakness, or advisory.
CVE-2024-33522Medium· 6.7Calico privilege escalation vulnerability
CVE-2022-28224Medium· 5.5Calico vulnerable to pod route hijacking
CVE-2023-41378High· 7.5Calico Typha denial of service vulnerability
CVE-2026-6720HighCalico Inserts Sensitive Information into Log File