Lucene search

K
cveGitHub_MCVE-2024-28248
HistoryMar 18, 2024 - 10:15 p.m.

CVE-2024-28248

2024-03-1822:15:08
CWE-693
GitHub_M
web.nvd.nist.gov
66
cilium
ebpf
http policies
security patch

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

48.0%

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 and prior to versions 1.13.13, 1.14.8, and 1.15.2, Cilium’s HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped. This issue has been patched in Cilium 1.15.2, 1.14.8, and 1.13.13. There are no known workarounds for this issue.

Affected configurations

Vulners
Node
ciliumciliumRange1.13.91.13.13
OR
ciliumciliumRange1.14.01.14.8
OR
ciliumciliumRange1.15.01.15.2
VendorProductVersionCPE
ciliumcilium*cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "cilium",
    "product": "cilium",
    "versions": [
      {
        "version": ">= 1.13.9, < 1.13.13",
        "status": "affected"
      },
      {
        "version": ">= 1.14.0, < 1.14.8",
        "status": "affected"
      },
      {
        "version": ">= 1.15.0, < 1.15.2",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

48.0%