Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTP…
Medium CVSS 5.9
Summary
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb Patch
- https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857 Patch
- https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b Patch
- https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512ca Patch
- https://github.com/cilium/cilium/releases/tag/v1.17.17 Release Notes
- https://github.com/cilium/cilium/releases/tag/v1.18.11 Release Notes
- https://github.com/cilium/cilium/releases/tag/v1.19.5 Release Notes
- https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj Vendor Advisory
Timeline
- nvd_ingest NVD