In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies:
This issue affects:
routingMode=native):
routingMode=tunnel):
encryption.wireguard.encapsulate is set to false (default).This issue has been resolved in:
routingMode=native):
routingMode=tunnel):
encryption.wireguard.encapsulate must be set to true.There is no workaround to this issue.
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @brb, @giorio94, @gandro and @jschwinger233 for their work on triaging and remediating this issue.
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you found a related vulnerability, we strongly encourage you to report security vulnerabilities to our private security mailing list at security@cilium.io. This is a private mailing list where only members of the Cilium internal security team are subscribed to, and your report will be treated as top priority.
{
"nvd_published_at": "2024-03-18T22:15:08Z",
"github_reviewed": true,
"github_reviewed_at": "2024-03-18T20:33:32Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-311",
"CWE-319"
]
}