CVE-2024-25630
published 2024-02-20CVE-2024-25630: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the…
PriorityP425medium5.3CVSS 3.1
AVAACHPRNUINSUCHINAN
EPSS
0.18%
8.2th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingress and health endpoints is not encrypted. This issue affects Cilium v1.14 before v1.14.7 and has been patched in Cilium v1.14.7. There is no workaround to this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | — | — |
| cilium | cilium | >= 1.14.0 < 1.14.7 | 1.14.7 |
| github.com | cilium_cilium | >= 1.14.0 < 1.14.7 | 1.14.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Unencrypted ingress/health traffic when using Wireguard transparent encryption in github.com/cilium/cilium
osv·2024-06-04
CVE-2024-25630 Unencrypted ingress/health traffic when using Wireguard transparent encryption in github.com/cilium/cilium
Unencrypted ingress/health traffic when using Wireguard transparent encryption in github.com/cilium/cilium
Unencrypted ingress/health traffic when using Wireguard transparent encryption in github.com/cilium/cilium
GHSA
Unencrypted ingress/health traffic when using Wireguard transparent encryption
ghsa·2024-02-20
CVE-2024-25630 [MEDIUM] CWE-311 Unencrypted ingress/health traffic when using Wireguard transparent encryption
Unencrypted ingress/health traffic when using Wireguard transparent encryption
### Impact
For Cilium users who are using CRDs to store Cilium state (the default configuration) and [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg), responses from pods to the Ingress and health endpoints are not encrypted. Traffic from the Ingress and health endpoints to pods is not affected by this issue. The health endpoint is only used for Cilium's internal health checks.
### Patches
This issue affects Cilium v1.14 before v1.14.7.
This issue has been patched in Cilium v1.14.7.
### Workarounds
There is no workaround to this issue - affected users are encouraged to upgrade.
### Acknowledgements
The Cilium community has worked t
OSV
Unencrypted ingress/health traffic when using Wireguard transparent encryption
osv·2024-02-20
CVE-2024-25630 [MEDIUM] Unencrypted ingress/health traffic when using Wireguard transparent encryption
Unencrypted ingress/health traffic when using Wireguard transparent encryption
### Impact
For Cilium users who are using CRDs to store Cilium state (the default configuration) and [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg), responses from pods to the Ingress and health endpoints are not encrypted. Traffic from the Ingress and health endpoints to pods is not affected by this issue. The health endpoint is only used for Cilium's internal health checks.
### Patches
This issue affects Cilium v1.14 before v1.14.7.
This issue has been patched in Cilium v1.14.7.
### Workarounds
There is no workaround to this issue - affected users are encouraged to upgrade.
### Acknowledgements
The Cilium community has worked t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wghttps://github.com/cilium/cilium/releases/tag/v1.14.7https://github.com/cilium/cilium/security/advisories/GHSA-7496-fgv9-xw82https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wghttps://github.com/cilium/cilium/releases/tag/v1.14.7https://github.com/cilium/cilium/security/advisories/GHSA-7496-fgv9-xw82
2024-02-20
Published