Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.15.2, 1.14.8, and 1.13.13. There is no known workaround for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0947 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.15.2, 1.14.8, and 1.13.13. There is no known workaround for this issue. |
Github GHSA |
GHSA-j89h-qrvr-xc36 | Unencrypted traffic between nodes when using IPsec and L7 policies |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cilium
Cilium cilium |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cilium
Cilium cilium |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T00:48:49.660Z
Reserved: 2024-03-07T14:33:30.036Z
Link: CVE-2024-28249
Updated: 2024-05-23T19:01:18.629Z
Status : Analyzed
Published: 2024-03-18T22:15:08.503
Modified: 2025-01-09T16:46:53.507
Link: CVE-2024-28249
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA