CVE-2025-23047
published 2025-01-22CVE-2025-23047: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.50%
41.8th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure for users of Cilium versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4 who deploy Hubble UI using either Cilium CLI or via the Cilium Helm chart. A user with access to a Hubble UI instance affected by this issue could leak configuration details about the Kubernetes cluster which Hubble UI is monitoring, including node names, IP addresses, and other metadata about workloads and the cluster networking configuration. In order for this vulnerability to be exploited, a victim would have to first visit a malicious page. This issue is fixed in Cilium v1.14.18, v1.15.12, and v1.16.5. As a workaround, users who deploy Hubble UI using the Cilium Helm chart directly can remove the CORS headers from the Helm template as shown in the patch from commit a3489f190ba6e87b5336ee685fb6c80b1270d06d.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.14.0 < 1.14.19 | 1.14.19 |
| cilium | cilium | >= 1.15.0 < 1.15.13 | 1.15.13 |
| cilium | cilium | >= 1.16.0 < 1.16.6 | 1.16.6 |
| github.com | cilium_cilium | >= 1.14.0 < 1.14.19 | 1.14.19 |
| github.com | cilium_cilium | >= 1.15.0 < 1.15.13 | 1.15.13 |
| github.com | cilium_cilium | >= 1.16.0 < 1.16.6 | 1.16.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cilium has an information leakage via insecure default Hubble UI CORS header in github.com/cilium/cilium
osv·2025-01-28
CVE-2025-23047 Cilium has an information leakage via insecure default Hubble UI CORS header in github.com/cilium/cilium
Cilium has an information leakage via insecure default Hubble UI CORS header in github.com/cilium/cilium
Cilium has an information leakage via insecure default Hubble UI CORS header in github.com/cilium/cilium
OSV
Cilium has an information leakage via insecure default Hubble UI CORS header
osv·2025-01-22
CVE-2025-23047 [MEDIUM] Cilium has an information leakage via insecure default Hubble UI CORS header
Cilium has an information leakage via insecure default Hubble UI CORS header
### Impact
For users who deploy Hubble UI using either Cilium CLI or via the Cilium Helm chart, an insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure. A user with access to a Hubble UI instance affected by this issue could leak configuration details about the Kubernetes cluster which Hubble UI is monitoring, including node names, IP addresses, and other metadata about workloads and the cluster networking configuration. In order for this vulnerability to be exploited, a victim would have to first visit a malicious page.
### Patches
This issue was patched in https://github.com/cilium/cilium/commit/a3489f190ba6e87b5336ee685fb6c80b1270d06d
This issue affects:
- Cili
GHSA
Cilium has an information leakage via insecure default Hubble UI CORS header
ghsa·2025-01-22
CVE-2025-23047 [MEDIUM] CWE-200 Cilium has an information leakage via insecure default Hubble UI CORS header
Cilium has an information leakage via insecure default Hubble UI CORS header
### Impact
For users who deploy Hubble UI using either Cilium CLI or via the Cilium Helm chart, an insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure. A user with access to a Hubble UI instance affected by this issue could leak configuration details about the Kubernetes cluster which Hubble UI is monitoring, including node names, IP addresses, and other metadata about workloads and the cluster networking configuration. In order for this vulnerability to be exploited, a victim would have to first visit a malicious page.
### Patches
This issue was patched in https://github.com/cilium/cilium/commit/a3489f190ba6e87b5336ee685fb6c80b1270d06d
This issue affects:
- Cili
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-22
Published