Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-42486

Опубликовано: 16 авг. 2024
Источник: nvd
CVSS3: 5.4
CVSS3: 7.2
EPSS Низкий

Описание

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
Версия от 1.15.0 (включая) до 1.15.8 (включая)
cpe:2.3:a:cilium:cilium:1.16.0:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00301
Низкий

5.4 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4
redhat
больше 1 года назад

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

CVSS3: 5.4
debian
больше 1 года назад

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 5.4
github
больше 1 года назад

Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API

EPSS

Процентиль: 53%
0.00301
Низкий

5.4 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-200