Логотип exploitDog
bind:CVE-2024-42486
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-42486

Количество 4

Количество 4

redhat логотип

CVE-2024-42486

больше 1 года назад

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2024-42486

больше 1 года назад

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-42486

больше 1 года назад

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-vwf8-q6fw-4wcm

больше 1 года назад

Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-42486

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

CVSS3: 4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-42486

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-42486

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-vwf8-q6fw-4wcm

Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу