Bug 2034838 - An external router can inject routes if no service is added
Summary: An external router can inject routes if no service is added
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Networking
Version: 4.10
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
: 4.10.0
Assignee: Federico Paolinelli
QA Contact: Arti Sood
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-12-22 10:19 UTC by Federico Paolinelli
Modified: 2022-03-10 16:36 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-03-10 16:36:03 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift metallb pull 23 0 None Merged Bug 2035250: Upstream alignement 2021-12-24 14:07:49 UTC
Red Hat Product Errata RHSA-2022:0056 0 None None None 2022-03-10 16:36:18 UTC

Description Federico Paolinelli 2021-12-22 10:19:52 UTC
Description of problem:

Since we are adding the route filtering only in the advertisement section, it could happen that a configured neighbor is able to inject routes if no services are advertised.

Comment 8 errata-xmlrpc 2022-03-10 16:36:03 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: OpenShift Container Platform 4.10.3 security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2022:0056


Note You need to log in before you can comment on or make changes to this bug.