{"id":"GHSA-9394-xfq9-6qrp","summary":"Calico vulnerable to pod route hijacking","details":"Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a floating IP annotation to a pod even if the feature is not enabled. This may allow the attacker to intercept and reroute traffic to their compromised pod.","aliases":["CVE-2022-28224"],"modified":"2026-08-07T08:12:05.645787966Z","published":"2022-06-07T00:00:33Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-02-02T20:16:57Z","nvd_published_at":"2022-06-06T18:15:00Z","cwe_ids":["CWE-20","CWE-200"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28224"},{"type":"PACKAGE","url":"https://github.com/projectcalico/calico"},{"type":"WEB","url":"https://www.tigera.io/security-bulletins-tta-2022-001"}],"affected":[{"package":{"name":"github.com/projectcalico/calico","ecosystem":"Go","purl":"pkg:golang/github.com/projectcalico/calico"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.22.0"},{"fixed":"3.22.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-9394-xfq9-6qrp/GHSA-9394-xfq9-6qrp.json"}},{"package":{"name":"github.com/projectcalico/calico","ecosystem":"Go","purl":"pkg:golang/github.com/projectcalico/calico"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.21.0"},{"fixed":"3.21.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-9394-xfq9-6qrp/GHSA-9394-xfq9-6qrp.json"}},{"package":{"name":"github.com/projectcalico/calico","ecosystem":"Go","purl":"pkg:golang/github.com/projectcalico/calico"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.20.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-9394-xfq9-6qrp/GHSA-9394-xfq9-6qrp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"}]}