Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a port range `AND` 2. A Layer 7 allow policy that selects a specific port within the first policy's range the Layer 7 enforcement would not occur for the traffic selected by the Layer 7 policy. This issue only affects users who use Cilium's port range functionality, which was introduced in Cilium v1.16. This issue is patched in PR #35150. This issue affects Cilium v1.16 between v1.16.0 and v1.16.3 inclusive. This issue is patched in Cilium v1.16.4. Users are advised to upgrade. Users with network policies that match the pattern described above can work around the issue by rewriting any policies that use port ranges to individually specify the ports permitted for traffic.
History

Tue, 26 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Cilium
Cilium cilium
CPEs cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
Vendors & Products Cilium
Cilium cilium
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 Nov 2024 19:00:00 +0000

Type Values Removed Values Added
Description Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a port range `AND` 2. A Layer 7 allow policy that selects a specific port within the first policy's range the Layer 7 enforcement would not occur for the traffic selected by the Layer 7 policy. This issue only affects users who use Cilium's port range functionality, which was introduced in Cilium v1.16. This issue is patched in PR #35150. This issue affects Cilium v1.16 between v1.16.0 and v1.16.3 inclusive. This issue is patched in Cilium v1.16.4. Users are advised to upgrade. Users with network policies that match the pattern described above can work around the issue by rewriting any policies that use port ranges to individually specify the ports permitted for traffic.
Title Layer 7 policy enforcement may not occur in policies with wildcarded port ranges in Cilium
Weaknesses CWE-755
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-25T18:49:15.616Z

Updated: 2024-11-26T14:28:59.941Z

Reserved: 2024-11-11T18:49:23.561Z

Link: CVE-2024-52529

cve-icon Vulnrichment

Updated: 2024-11-26T14:28:52.950Z

cve-icon NVD

Status : Received

Published: 2024-11-25T19:15:11.373

Modified: 2024-11-25T19:15:11.373

Link: CVE-2024-52529

cve-icon Redhat

No data.