PT-2024-22364 · Cilium · Cilium
Giorio94
·
Published
2024-03-18
·
Updated
2025-01-09
·
CVE-2024-28249
CVSS v3.1
6.1
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cilium versions prior to 1.13.13
Cilium versions prior to 1.14.8
Cilium versions prior to 1.15.2
Cilium versions 1.4 through 1.12
Description
In Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted, and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue affects connections selected by a L7 Egress Network Policy or a DNS Policy in native routing mode, which is a known limitation of Cilium's IPsec encryption.
Recommendations
For Cilium versions prior to 1.13.13, update to version 1.13.13 or later.
For Cilium versions prior to 1.14.8, update to version 1.14.8 or later.
For Cilium versions prior to 1.15.2, update to version 1.15.2 or later.
For Cilium versions 1.4 through 1.12, update to a version outside of this range, such as 1.13.13, 1.14.8, or 1.15.2.
As a temporary workaround is not available, updating to the specified versions is the recommended course of action.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cilium