Security Advisory

CVE-2024-28248

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-03-18 21:31:51
Last updated 2024-08-02 00:48:49
Assigner GitHub_M
State PUBLISHED

Description

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 and prior to versions 1.13.13, 1.14.8, and 1.15.2, Ciliums HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped. This issue has been patched in Cilium 1.15.2, 1.14.8, and 1.13.13. There are no known workarounds for this issue.