Database/Container, Kubernetes & orchestration
Cilium: Agent pod hostPath allows writing to /opt/cni/bin, replacing the CNI binary on the host
CVSS 4.4CVE-2023-27593Container, Kubernetes & orchestrationcurated
Impact
Agent pod hostPath allows writing to /opt/cni/bin, replacing the CNI binary on the host
Who can reach it
Attacker with access to a Cilium agent pod
What to do
Rolling Cilium upgrade; restrict who can exec into kube-system
References
Related entries
- Cilium: Deny rules for prefixes broader than /32 can be ignoredCVE-2024-47825 · CiliumMedium
- Cilium: WireGuard encryption gap in a specific Cilium configurationCVE-2025-32793 · CiliumMedium
- Cilium: Egress policies referencing AWS security group IDs are misappliedCVE-2025-64715 · CiliumMedium
- Cilium: With L7 enabled, the embedded Envoy exposes a world-accessible admin.sock on the clusterCVE-2026-49445 · CiliumCritical
- Cilium: Incorrect default permissions on Cilium-managed host paths allow privilege escalationCVE-2022-29178 · CiliumHigh
- Cilium: IPsec transparent encryption is cryptographically ineffectiveCVE-2024-28860 · CiliumHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.