CVE-2022-0567: Ovn Ovn-Kubernetes

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.

Affected products

  • Ovn Ovn-Kubernetes: before 4.7.47 (fixed in 4.7.47); from 4.8.0, before 4.8.36 (fixed in 4.8.36); from 4.9.0, before 4.9.27 (fixed in 4.9.27); from 4.10.0, before 4.10.8 (fixed in 4.10.8)

Published 2022-04-20. Last modified 2026-06-17.