Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, identifying external traffic as coming from the host on which Cilium is running. As a consequence, network policies for that cluster might be bypassed, depending on the specific network policies enabled.
This issue only manifests when Cilium is routing IPv6 traffic and NodePorts are used to route traffic to pods. IPv6 and endpoint routes are both disabled by default.
The problem has been fixed and is available on versions 1.11.15, 1.12.8, and 1.13.1. As a workaround, disable IPv6 routing.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-03-17T19:56:43.687Z
Updated: 2024-08-02T12:16:35.954Z
Reserved: 2023-03-04T01:03:53.636Z
Link: CVE-2023-27594
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-17T20:15:13.583
Modified: 2024-11-21T07:53:13.370
Link: CVE-2023-27594
Redhat
No data.