- Description
- Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium. This issue has been patched in versions 1.15.16, 1.16.9, and 1.17.3. There are no workarounds available for this issue.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- cilium
CVSS 3.1
- Type
- Primary
- Base score
- 4
- Impact score
- 1.4
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
- Severity
- MEDIUM
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B7E61719-4A1B-478F-8674-7A5340B83B9B",
"versionEndExcluding": "1.15.16",
"versionStartIncluding": "1.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*",
"matchCriteriaId": "560F6A3B-0879-42F9-94B4-80D6036388EE",
"versionEndExcluding": "1.16.9",
"versionStartIncluding": "1.16.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CE716081-3B6C-4F7C-8798-C010904E8BF4",
"versionEndExcluding": "1.17.3",
"versionStartIncluding": "1.17.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]