PT-2024-29984 · Cilium · Cilium

Published

2024-08-15

·

Updated

2024-09-30

·

CVE-2024-42487

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cilium versions 1.15.0 through 1.15.7 Cilium version 1.16.0
Description The Gateway API HTTPRoutes and GRPCRoutes in Cilium do not follow the match precedence specified in the Gateway API specification. Request headers are matched before request methods, contrary to the specification that requires request methods to be respected before headers are matched. This could result in unexpected behavior with security implications. If users create Gateway API resources that use both request headers and request methods to route to different destinations, then traffic may be delivered to the incorrect backend, potentially allowing access to information that was not intended to be accessed.
Recommendations For Cilium versions 1.15.0 through 1.15.7, update to version 1.15.8 to resolve the issue. For Cilium version 1.16.0, update to version 1.16.1 to resolve the issue. As a temporary workaround is not available, updating to the fixed version is the recommended course of action.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-CILIUM-2024-42487
BIT-CILIUM-OPERATOR-2024-42487
BIT-HUBBLE-RELAY-2024-42487
CVE-2024-42487
GHSA-QCM3-7879-XCWW
GO-2024-3071

Affected Products

Cilium