Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors…
Medium CVSS 5.4
Summary
Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/cilium/cilium/commit/1c84ae3b58a7cd54f7ee355e6c524c82f620eae8 Patch
- https://github.com/cilium/cilium/commit/bacea640404c0805c23515353dc1681c5bf35171 Patch
- https://github.com/cilium/cilium/pull/46305 Patch
- https://github.com/cilium/cilium/pull/46456 Patch
- https://github.com/cilium/cilium/releases/tag/v1.19.5 Release Notes
- https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r Vendor Advisory
Timeline
- nvd_ingest NVD