Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8006 | Cilium node based network policies may incorrectly allow workload traffic |
Github GHSA |
GHSA-c6pf-2v8j-96mc | Cilium node based network policies may incorrectly allow workload traffic |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 04 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:* |
Wed, 26 Mar 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 24 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium. This issue affects: Cilium v1.16 between v1.16.0 and v1.16.7 inclusive and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.16.8 and v1.17.2. Users can work around this issue by ensuring that the labels used in `fromNodes` and `toNodes` fields are used exclusively by nodes and not by other endpoints. | |
| Title | Node based network policies may incorrectly allow workload traffic | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-24T19:29:46.075Z
Reserved: 2025-03-17T12:41:42.567Z
Link: CVE-2025-30163
Updated: 2025-03-24T19:29:42.821Z
Status : Analyzed
Published: 2025-03-24T19:15:52.937
Modified: 2025-09-04T15:51:32.597
Link: CVE-2025-30163
OpenCVE Enrichment
Updated: 2025-07-12T15:26:06Z
EUVD
Github GHSA