Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTP…
中危 CVSS 5.9
摘要
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb Patch
- https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857 Patch
- https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b Patch
- https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512ca Patch
- https://github.com/cilium/cilium/releases/tag/v1.17.17 Release Notes
- https://github.com/cilium/cilium/releases/tag/v1.18.11 Release Notes
- https://github.com/cilium/cilium/releases/tag/v1.19.5 Release Notes
- https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj Vendor Advisory
时间线
- nvd_ingest NVD