PT-2023-21573 · Etcd+1 · Etcd+1

Giorio94

·

Publicado

2023-03-21

·

Atualizado

2024-08-20

·

CVE-2023-28114

CVSS v3.1

4.8

Média

VetorAV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions cilium-cli versions prior to 0.13.2
Description The issue arises when cilium-cli is used to configure cluster mesh functionality, potentially removing the enforcement of user permissions on the etcd store. This occurs due to an incorrect mount point specification, causing the settings specified by the initContainer to be overwritten. As a result, an attacker with access to a valid key and certificate for the compromised etcd cluster could modify its state.
Recommendations For versions prior to 0.13.2, update to version 0.13.2 to resolve the issue. As a temporary workaround, consider using Cilium's Helm charts to create the cluster instead of cilium-cli.

Exploit

Correção

Improper Handling of Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28114
GHSA-6F27-3P6C-P5JC
GO-2023-1653

Produtos afetados

Cilium-Cli
Etcd