PT-2023-22078 · Cilium · Cilium
Meyskens
·
Published
2023-04-18
·
Updated
2024-08-20
·
CVE-2023-29002
CVSS v3.1
7.2
High
| Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cilium versions prior to 1.11.16
Cilium versions prior to 1.12.9
Cilium versions prior to 1.13.2
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the
cilium-secrets namespace, which could include data such as TLS private keys for Ingress and GatewayAPI resources. An attacker with access to debug output from the Cilium containers could use the resulting output to intercept and modify traffic to and from the affected cluster. Output of the sensitive information would occur at Cilium agent restart, when secrets in the namespace are modified, and on creation of Ingress or GatewayAPI resources.Recommendations
For Cilium versions prior to 1.11.16, update to version 1.11.16 or later.
For Cilium versions prior to 1.12.9, update to version 1.12.9 or later.
For Cilium versions prior to 1.13.2, update to version 1.13.2 or later.
As a temporary workaround, consider disabling debug mode until a patch is available.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cilium