Skip to main content

Threats Tagged 'ghsa-3fcv-jvfp-m4q9'

View all threats tagged with 'ghsa-3fcv-jvfp-m4q9'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: ghsa-3fcv-jvfp-m4q9

Threats Tagged 'ghsa-3fcv-jvfp-m4q9'

Click on any threat for detailed analysis and mitigation recommendations

### Impact When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive information or allow disruptive administrative operations, such as: - Exposing TLS secrets - Disrupting traffic in the cluster - Terminating the Envoy process This issue affects both the embedded and standalone Envoy deployment models. ### Patches This issue affects: - Cilium v1.19 between v1.19.0 and v1.19.1 inclusive - Cilium v1.18 between v1.18.0 and v1.18.7 inclusive - All versions of Cilium prior to v1.17.14 This issue has been patched in https://github.com/cilium/cilium/pull/44512, included in: - Cilium v1.19.2 - Cilium v1.18.8 - Cilium v1.17.14 ### Workarounds There is no known workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to [moemen](https://github.com/moemen) for reporting the issue and [0xch4z](https://github.com/0xch4z) for their work on triaging and remediating this issue. ### For more information If there are any questions or comments about this advisory, please reach out on [Slack (https://docs.cilium.io/en/latest/community/community/). If anyone thinks they have found a vulnerability affecting Cilium, it is strongly encouraged to report it to the security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and the report will be treated as a top priority.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: ghsa-3fcv-jvfp-m4q9
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses