Database/Container, Kubernetes & orchestration
Cilium: IPsec transparent encryption is cryptographically ineffective
CVSS 8.0CVE-2024-28860Container, Kubernetes & orchestrationcurated
Impact
IPsec transparent encryption is cryptographically ineffective; inter-node traffic can be decrypted or forged
Who can reach it
Anyone with access to the underlay network between nodes
What to do
Upgrade Cilium and rotate IPsec keys; assume prior inter-node traffic was exposed
References
Related entries
- Cilium: cilium-bugtool output contains sensitive dataCVE-2024-37307 · CiliumHigh
- Cilium: cilium-bugtool leaks sensitive data (recurrence of the 2024 issue)CVE-2026-41520 · CiliumHigh
- Cilium: An attacker able to update pod labels causes Cilium to apply the wrong network policyCVE-2023-39347 · CiliumHigh
- Cilium: After a container escape, an attacker can install eBPF programs and take over the node dataplaneCVE-2022-29179 · CiliumHigh
- Cilium: Debug mode logs the contents of the cilium-secrets namespace, including TLS private keysCVE-2023-29002 · CiliumHigh
- Cilium: HTTP policies not consistently applied to all trafficCVE-2024-28248 · CiliumHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.