You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than /32 may be ignored if there is a policy rule referencing a more narrow prefix (CIDRSet or toFQDN) and this narrower policy rule specifies either enableDefaultDeny: false or - toEntities: all. Note that a rule specifying toEntities: world or toEntities: 0.0.0.0/0 is insufficient, it must be to entity all.This issue has been patched in Cilium v1.14.16 and v1.15.10. As th...
Advisory CVE-2024-47825 references a vulnerability in the following Go modules:
Description:
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than
/32
may be ignored if there is a policy rule referencing a more narrow prefix (CIDRSet
ortoFQDN
) and this narrower policy rule specifies eitherenableDefaultDeny: false
or- toEntities: all
. Note that a rule specifyingtoEntities: world
ortoEntities: 0.0.0.0/0
is insufficient, it must be to entityall
.This issue has been patched in Cilium v1.14.16 and v1.15.10. As th...References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: