漏洞标题
Cilium eBPF过滤器可能在代理重启时暂时移除
漏洞描述信息
在代理重启期间,Cilium eBPF过滤器可能会被暂时删除
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
漏洞类别
N/A
漏洞标题
Cilium eBPF filters may be temporarily removed during agent restart
漏洞描述信息
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In version 1.13.0, when Cilium is started, there is a short period when Cilium eBPF programs are not attached to the host. During this period, the host does not implement any of Cilium's featureset. This can cause disruption to newly established connections during this period due to the lack of Load Balancing, or can cause Network Policy bypass due to the lack of Network Policy enforcement during the window. This vulnerability impacts any Cilium-managed endpoints on the node (such as Kubernetes Pods), as well as the host network namespace (including Host Firewall). This vulnerability is fixed in Cilium 1.13.1 or later. Cilium releases 1.12.x, 1.11.x, and earlier are not affected. There are no known workarounds.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
漏洞类别
对异常条件的处理不恰当
漏洞标题
Cilium 安全漏洞
漏洞描述信息
Cilium是一个开源软件。用于提供和透明地保护应用程序工作负载(如应用程序容器或进程)之间的网络连接和负载平衡。 Cilium 1.13.0版本存在安全漏洞,该漏洞源于当Cilium启动时,有一小段时间Cilium eBPF程序没有附加到主机上。
CVSS信息
N/A
漏洞类别
其他