Database/Container, Kubernetes & orchestration
Cilium: An attacker able to update pod labels causes Cilium to apply the wrong network policy
CVSS 7.6CVE-2023-39347Container, Kubernetes & orchestrationcurated
Impact
An attacker able to update pod labels causes Cilium to apply the wrong network policy
Who can reach it
Cluster user with namespace access
What to do
Rolling Cilium upgrade; restrict pod label patch RBAC
References
Related entries
- Cilium: After a container escape, an attacker can install eBPF programs and take over the node dataplaneCVE-2022-29179 · CiliumHigh
- Cilium: Debug mode logs the contents of the cilium-secrets namespace, including TLS private keysCVE-2023-29002 · CiliumHigh
- Cilium: HTTP policies not consistently applied to all trafficCVE-2024-28248 · CiliumHigh
- Cilium: A user who can create CiliumNetworkPolicy in one namespace affects traffic cluster-wideCVE-2023-41333 · CiliumMedium
- Cilium: Agent race condition drops pod labels, so the wrong (often more permissive) policy appliesCVE-2024-42488 · CiliumMedium
- Cilium: On agent start, eBPF programs are briefly detached, so traffic bypasses NetworkPolicyCVE-2023-27595 · CiliumMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.