CVE-2023-30851

CVSS V2 None CVSS V3 None
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those endpoints. In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies. This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.
Overview
  • CVE ID
  • CVE-2023-30851
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-05-25T17:47:51.095Z
  • Last Modified Date
  • 2023-05-25T17:47:51.095Z
History
Created Old Value New Value Data Type Notes
2024-06-25 17:26:33 Added to TrackCVE