CVE Vulnerabilities

CVE-2024-28248

Protection Mechanism Failure

Published: Mar 18, 2024 | Modified: Jan 09, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 and prior to versions 1.13.13, 1.14.8, and 1.15.2, Ciliums HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped. This issue has been patched in Cilium 1.15.2, 1.14.8, and 1.13.13. There are no known workarounds for this issue.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

Name Vendor Start Version End Version
Cilium Cilium 1.13.9 (including) 1.13.13 (excluding)
Cilium Cilium 1.14.0 (including) 1.14.8 (excluding)
Cilium Cilium 1.15.0 (including) 1.15.2 (excluding)

References