BIT-cilium-2024-42488

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/cilium/BIT-cilium-2024-42488.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-cilium-2024-42488
Aliases
Published
2024-08-17T07:16:31.051Z
Modified
2024-08-17T08:12:08.904950Z
Summary
[none]
Details

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass. This issue has been patched in Cilium v1.14.14 and v1.15.8 As the underlying issue depends on a race condition, users unable to upgrade can restart the Cilium agent on affected nodes until the affected policies are confirmed to be working as expected.

Database specific
{
    "cpes": [
        "cpe:2.3:a:cilium:cilium:*:*:*:*:*:go:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / cilium

Package

Name
cilium
Purl
pkg:bitnami/cilium

Severity

  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.14.14
Introduced
1.15.0
Fixed
1.15.8