Описание
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium. This issue has been patched in versions 1.15.16, 1.16.9, and 1.17.3. There are no workarounds available for this issue.
Ссылки
- Patch
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.13.0 (включая) до 1.15.16 (исключая)Версия от 1.16.0 (включая) до 1.16.9 (исключая)Версия от 1.17.0 (включая) до 1.17.3 (исключая)
Одно из
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00009
Низкий
4 Medium
CVSS3
Дефекты
CWE-319
CWE-362
Связанные уязвимости
CVSS3: 4
debian
10 месяцев назад
Cilium is a networking, observability, and security solution with an e ...
CVSS3: 4
github
10 месяцев назад
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
EPSS
Процентиль: 1%
0.00009
Низкий
4 Medium
CVSS3
Дефекты
CWE-319
CWE-362