Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-42486

Опубликовано: 16 авг. 2024
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Network Observability Operatornetwork-observability/network-observability-ebpf-agent-rhel9Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel9Not affected
Power monitoring for Red Hat OpenShiftkepler-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/prometheus-rhel8Not affected
Red Hat Enterprise Linux 10buildahNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2305326cilium/ebpf: Gateway resources continue to establish sessions using revoked ReferenceGrants

EPSS

Процентиль: 53%
0.00301
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

CVSS3: 5.4
debian
больше 1 года назад

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 5.4
github
больше 1 года назад

Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API

EPSS

Процентиль: 53%
0.00301
Низкий

4 Medium

CVSS3