Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45958
HistoryMar 21, 2024 - 6:42 a.m.

HTTP Policy Bypass

2024-03-2106:42:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
cilium
http
policy
bypass
vulnerability
inconsistencies
traffic
unauthorized access
information disclosure

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

48.0%

Cilium is vulnerable to HTTP Policy Bypass. The vulnerability is due to inconsistencies when applying HTTP policies. This inconsistency allows HTTP traffic to be incorrectly and intermittently forwarded when it should be dropped, potentially allowing unauthorized access or information disclosure.

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

48.0%