Описание
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled. This issue has been patched in versions 1.17.15, 1.18.9, and 1.19.3.
Ссылки
- ProductRelease Notes
- ProductRelease Notes
- ProductRelease Notes
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.17.15 (исключая)Версия от 1.18.0 (включая) до 1.18.9 (исключая)Версия от 1.19.0 (включая) до 1.19.3 (исключая)
Одно из
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
EPSS
Процентиль: 0%
0.00077
Низкий
7.9 High
CVSS3
4.4 Medium
CVSS3
Дефекты
CWE-200
CWE-312
Связанные уязвимости
CVSS3: 7.9
debian
3 месяца назад
Cilium is a networking, observability, and security solution with an e ...
CVSS3: 7.9
github
4 месяца назад
Cillium exposes sensitive information included in the cilium-bugtool debug archive
EPSS
Процентиль: 0%
0.00077
Низкий
7.9 High
CVSS3
4.4 Medium
CVSS3
Дефекты
CWE-200
CWE-312