Описание
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.
Ссылки
- Patch
- Patch
- Release Notes
- Release Notes
- Release Notes
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.17.14 (исключая)Версия от 1.18.0 (включая) до 1.18.8 (исключая)Версия от 1.19.0 (включая) до 1.19.2 (исключая)
Одно из
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00125
Низкий
9.2 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 9.2
debian
26 дней назад
Cilium is a networking, observability, and security solution. Prior to ...
CVSS3: 9.2
github
около 1 месяца назад
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
EPSS
Процентиль: 3%
0.00125
Низкий
9.2 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-732