PT-2024-22364 · Cilium · Cilium

Giorio94

·

Published

2024-03-18

·

Updated

2025-01-09

·

CVE-2024-28249

CVSS v3.1

6.1

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cilium versions prior to 1.13.13 Cilium versions prior to 1.14.8 Cilium versions prior to 1.15.2 Cilium versions 1.4 through 1.12
Description In Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted, and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue affects connections selected by a L7 Egress Network Policy or a DNS Policy in native routing mode, which is a known limitation of Cilium's IPsec encryption.
Recommendations For Cilium versions prior to 1.13.13, update to version 1.13.13 or later. For Cilium versions prior to 1.14.8, update to version 1.14.8 or later. For Cilium versions prior to 1.15.2, update to version 1.15.2 or later. For Cilium versions 1.4 through 1.12, update to a version outside of this range, such as 1.13.13, 1.14.8, or 1.15.2. As a temporary workaround is not available, updating to the specified versions is the recommended course of action.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CILIUM-2024-28249
BIT-CILIUM-OPERATOR-2024-28249
BIT-CILIUM-PROXY-2024-28249
BIT-HUBBLE-2024-28249
BIT-HUBBLE-RELAY-2024-28249
BIT-HUBBLE-UI-2024-28249
BIT-HUBBLE-UI-BACKEND-2024-28249
CVE-2024-28249
GHSA-J89H-QRVR-XC36
GO-2024-2656

Affected Products

Cilium