Логотип exploitDog
bind:CVE-2023-27594
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27594

Количество 3

Количество 3

nvd логотип

CVE-2023-27594

почти 3 года назад

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, identifying external traffic as coming from the host on which Cilium is running. As a consequence, network policies for that cluster might be bypassed, depending on the specific network policies enabled. This issue only manifests when Cilium is routing IPv6 traffic and NodePorts are used to route traffic to pods. IPv6 and endpoint routes are both disabled by default. The problem has been fixed and is available on versions 1.11.15, 1.12.8, and 1.13.1. As a workaround, disable IPv6 routing.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2023-27594

почти 3 года назад

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-8fg8-jh2h-f2hc

почти 3 года назад

Potential network policy bypass when routing IPv6 traffic

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-27594

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, identifying external traffic as coming from the host on which Cilium is running. As a consequence, network policies for that cluster might be bypassed, depending on the specific network policies enabled. This issue only manifests when Cilium is routing IPv6 traffic and NodePorts are used to route traffic to pods. IPv6 and endpoint routes are both disabled by default. The problem has been fixed and is available on versions 1.11.15, 1.12.8, and 1.13.1. As a workaround, disable IPv6 routing.

CVSS3: 4.2
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-27594

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 4.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-8fg8-jh2h-f2hc

Potential network policy bypass when routing IPv6 traffic

CVSS3: 4.2
0%
Низкий
почти 3 года назад

Уязвимостей на страницу