Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors…
中危 CVSS 5.4
摘要
Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/cilium/cilium/commit/1c84ae3b58a7cd54f7ee355e6c524c82f620eae8 Patch
- https://github.com/cilium/cilium/commit/bacea640404c0805c23515353dc1681c5bf35171 Patch
- https://github.com/cilium/cilium/pull/46305 Patch
- https://github.com/cilium/cilium/pull/46456 Patch
- https://github.com/cilium/cilium/releases/tag/v1.19.5 Release Notes
- https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r Vendor Advisory
时间线
- nvd_ingest NVD