Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43413
HistorySep 28, 2023 - 6:26 a.m.

Denial Of Service (DoS)

2023-09-2806:26:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
vulnerability
l7 proxy
cilium agent
denial of service
software

3.5 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

0.0004 Low

EPSS

Percentile

9.0%

github.com/cilium/cilium is vulnerable to Denial of Service (DoS). The vulnerability is due to a lack of checks to confirm if the L7 proxy is enabled or disabled before processing the proxyVisibility annotations. When the L7 proxy is disabled, any workload with these annotations can crash the Cilium agent on the node where it’s scheduled, which This results in a Denial of Service (DoS) for that specific node.

3.5 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:43413