CVE-2022-29179

    Dashboard / Vulnerabilities / CVE-2022-29179

    CVE-2022-29179

    Published: 20 May 2022Last Modified: 12 Aug 2026

    Summary: Improper Privilege Management in Cilium

    Details: Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium's Kubernetes service account. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. There are no known workarounds available.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v1.10.5
    v1.10.8
    v1.10.10
    v1.10.9
    v1.10.7
    v1.10.6
    v1.10.4
    v1.10.2
    v1.10.3
    v1.10.1
    v1.10.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-29179 | CVE-DB