Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:48489
HistoryAug 19, 2024 - 8:58 a.m.

Sensitive Information Exposure

2024-08-1908:58:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
cilium
gatewayapi
vulnerability
github
sensitive information exposure
software

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

AI Score

6.5

Confidence

Low

github.com/cilium/cilium is vulnerable to Sensitive Information Exposure. The vulnerability is caused due to not propagating ReferenceGrant changes in Cilium’s GatewayAPI controller. This can lead to Gateway resources being able to access secrets for longer than intended or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

AI Score

6.5

Confidence

Low