Database/Container, Kubernetes & orchestration
Cilium: Debug mode logs the contents of the cilium-secrets namespace, including TLS private keys
CVSS 7.2CVE-2023-29002Container, Kubernetes & orchestrationcurated
Impact
Debug mode logs the contents of the cilium-secrets namespace, including TLS private keys
Who can reach it
Anyone with log-pipeline read access
What to do
Disable agent debug mode; rotate the TLS keys in cilium-secrets; scrub logs
References
Related entries
- Cilium: HTTP policies not consistently applied to all trafficCVE-2024-28248 · CiliumHigh
- Cilium: A user who can create CiliumNetworkPolicy in one namespace affects traffic cluster-wideCVE-2023-41333 · CiliumMedium
- Cilium: Agent race condition drops pod labels, so the wrong (often more permissive) policy appliesCVE-2024-42488 · CiliumMedium
- Cilium: On agent start, eBPF programs are briefly detached, so traffic bypasses NetworkPolicyCVE-2023-27595 · CiliumMedium
- Cilium: Insecure default Access-Control-Allow-Origin in Hubble UI exposes sensitive observability dataCVE-2025-23047 · CiliumMedium
- Cilium: WireGuard transparent encryption not applied to some pod trafficCVE-2024-25630 · CiliumMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.