Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted. This issue affects Cilium v1.14 before v1.14.7 and has been patched in Cilium v1.14.7. There is no workaround to this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0762 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted. This issue affects Cilium v1.14 before v1.14.7 and has been patched in Cilium v1.14.7. There is no workaround to this issue. |
Github GHSA |
GHSA-x989-52fc-4vr4 | Unencrypted traffic between pods when using Wireguard and an external kvstore |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Dec 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cilium
Cilium cilium |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cilium
Cilium cilium |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-26T14:46:55.989Z
Reserved: 2024-02-08T22:26:33.512Z
Link: CVE-2024-25631
Updated: 2024-08-01T23:44:09.675Z
Status : Analyzed
Published: 2024-02-20T18:15:53.117
Modified: 2024-12-18T17:17:13.857
Link: CVE-2024-25631
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA