Cilium

Cilium

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 27.09.2023 15:19:30
  • Zuletzt bearbeitet 21.11.2024 08:21:05

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In Cilium clusters where Cilium's Layer 7 proxy has been disabled, creating workloads with `policy.cilium.io/proxy-visibility` annotations (in Cilium >= v1.13)...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 27.09.2023 15:18:55
  • Zuletzt bearbeitet 21.11.2024 08:15:12

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to update pod labels can cause Cilium to apply incorrect network policies. This issue arises due to the fact that on pod update, C...

  • EPSS 0.06%
  • Veröffentlicht 15.06.2023 20:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:50

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when Gateway API is enabled in Cilium, the absence of a check on the namespace in which a ReferenceGrant is created could result in Ci...

  • EPSS 0.12%
  • Veröffentlicht 25.05.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 08:00:58

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those ...

  • EPSS 0.06%
  • Veröffentlicht 18.04.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:22

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the `cilium-secrets` namespace. This could include data such as TLS private keys for Ingress and Gatewa...

  • EPSS 0.05%
  • Veröffentlicht 17.03.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:53:13

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In version 1.13.0, when Cilium is started, there is a short period when Cilium eBPF programs are not attached to the host. During this period, the host does no...

  • EPSS 0.05%
  • Veröffentlicht 17.03.2023 20:15:13
  • Zuletzt bearbeitet 21.11.2024 07:53:13

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, identifying ex...

  • EPSS 0.02%
  • Veröffentlicht 17.03.2023 20:15:13
  • Zuletzt bearbeitet 21.11.2024 07:53:13

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, an attacker with access to a Cilium agent pod can write to `/opt/cni/bin` due to a `hostPath` mount of that dire...

  • EPSS 0.18%
  • Veröffentlicht 20.05.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:38

Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versions 1.9.16, 1.10.11, and 1.11.15 contains an incorrect default permissions vulnerability. Operating S...

  • EPSS 0.14%
  • Veröffentlicht 20.05.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:39

Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container runnin...