Impact
The vulnerability stems from Cilium’s handling of Envoy when Layer‑7 functionality is active. In versions before 1.17.14, 1.18.8, and 1.19.2, Envoy creates an admin.sock socket on each cluster node that is world‑accessible. A local attacker can connect to this socket, invoke Envoy admin endpoints, expose TLS secrets, manipulate or terminate traffic, and potentially bring down cluster routing. This flaw is a broken access control (CWE‑732). The defect has been remedied in the specified releases.
Affected Systems
Cilium Cilium networking stack, before the release of versions 1.17.14, 1.18.8, and 1.19.2. The issue occurs only when L7 functionality is active, affecting embedded or standalone Envoy instances on cluster nodes.
Risk and Exploitability
The vulnerability carries a high CVSS score of 9.2, indicating severe impact, yet the EPSS score is below 1%, suggesting exploitation chances are low at present. Because the exploit requires local access to the node, it is not an internet‑reachable vulnerability, but any compromised or improperly secured host can exploit it. The flaw is not listed in CISA’s KEV catalog and no public exploits are known, but the potential for cluster‑wide disruption warrants immediate attention.
OpenCVE Enrichment
Github GHSA