CVE-2024-28249
Unencrypted traffic between nodes with IPsec in github.com/cilium/cilium
6.1
MEDIUM
CVSS 3.1
EPSS 0.27%
描述
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.15.2, 1.14.8, and 1.13.13. There is no known workaround for this issue.
如何修補 CVE-2024-28249
要修補 CVE-2024-28249,請將受影響套件升級到下列已修補版本。
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
- —升級至 1.13.13 或更新版本
CVE-2024-28249 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(9)
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
- from 0, < 1.13.13
- from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |