CVE-2024-42488
- EPSS 0.04%
- Veröffentlicht 15.08.2024 21:15:17
- Zuletzt bearbeitet 27.09.2024 18:49:05
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in...
CVE-2024-42487
- EPSS 2.43%
- Veröffentlicht 15.08.2024 21:15:16
- Zuletzt bearbeitet 30.09.2024 18:31:04
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in t...
CVE-2024-37307
- EPSS 0.04%
- Veröffentlicht 13.06.2024 16:15:11
- Zuletzt bearbeitet 09.01.2025 16:37:54
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitive data when the tool is run (w...
CVE-2024-28860
- EPSS 0.03%
- Veröffentlicht 27.03.2024 19:15:48
- Zuletzt bearbeitet 02.09.2025 16:05:05
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective. In particular, C...
CVE-2024-28250
- EPSS 0.05%
- Veröffentlicht 18.03.2024 22:15:08
- Zuletzt bearbeitet 09.01.2025 16:47:40
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies Wireguard-e...
CVE-2024-28249
- EPSS 0.2%
- Veröffentlicht 18.03.2024 22:15:08
- Zuletzt bearbeitet 09.01.2025 16:46:53
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a no...
CVE-2024-28248
- EPSS 0.76%
- Veröffentlicht 18.03.2024 22:15:08
- Zuletzt bearbeitet 09.01.2025 16:40:56
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 and prior to versions 1.13.13, 1.14.8, and 1.15.2, Cilium's HTTP policies are not consistently applied to all traffic in the scope o...
CVE-2024-25631
- EPSS 0.05%
- Veröffentlicht 20.02.2024 18:15:53
- Zuletzt bearbeitet 18.12.2024 17:17:13
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted. This...
CVE-2024-25630
- EPSS 0.05%
- Veröffentlicht 20.02.2024 18:15:52
- Zuletzt bearbeitet 18.12.2024 17:17:18
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingress and hea...
CVE-2023-41333
- EPSS 0.01%
- Veröffentlicht 27.09.2023 15:19:30
- Zuletzt bearbeitet 21.11.2024 08:21:05
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to create or modify CiliumNetworkPolicy objects in a particular namespace is able to affect traffic on an entire Cilium cluster, p...