GPU VulnDB

Database/Container, Kubernetes & orchestration

Cilium: An attacker able to update pod labels causes Cilium to apply the wrong network policy

CVE-2023-39347Container, Kubernetes & orchestrationcurated

Impact

An attacker able to update pod labels causes Cilium to apply the wrong network policy

Who can reach it

Cluster user with namespace access

What to do

Rolling Cilium upgrade; restrict pod label patch RBAC

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.