Логотип exploitDog
bind:CVE-2023-30851
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-30851

Количество 3

Количество 3

nvd логотип

CVE-2023-30851

больше 2 лет назад

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those endpoints. In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies. This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2023-30851

больше 2 лет назад

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-2h44-x2wx-49f4

больше 2 лет назад

Potential HTTP policy bypass when using header rules in Cilium

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-30851

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those endpoints. In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies. This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-30851

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h44-x2wx-49f4

Potential HTTP policy bypass when using header rules in Cilium

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу